Lyposit is a Windows lockscreen ransomware family active from at least 2012 to 2013 and also referred to as Lucky LOCKER in some reporting. It operated as an affiliate-driven crimeware service and was distributed through broader malware and exploit-kit ecosystems, including botnet tasking and exploit-kit traffic chains. Observed delivery paths included compromised websites, malvertising, spam-linked infection chains, and secondary payload deployment from already infected hosts. Lyposit was also associated in some reporting with Bomba Locker and discussed alongside Urausy, Nymaim, and Reveton-style police locker operations.
Lyposit uses a multi-stage architecture. Documented samples include a Visual Basic dropper, an intermediate x86 loader, RC2-based decryption routines, and a final DLL or lockscreen payload. The malware dynamically resolves APIs, uses multiple threads, and stores encoded command-and-control information in its binary data, complicating analysis. It communicates with its infrastructure through Background Intelligent Transfer Service and WinINet, downloading configuration data or an HTML-based lock page tailored to the victim. The downloaded content is rendered full-screen, disables normal interaction such as scrolling, hides unrelated windows, and alters the visual environment to obstruct recovery. Some variants changed the Windows color scheme to black and red and disabled visual effects; some campaigns used region-specific imagery and messaging, including designs for the United States, United Kingdom, Germany, France, Portugal, Denmark, Ireland, and other countries. In some cases the displayed page visually imitated a Mac OS environment despite targeting Windows systems.
Persistence mechanisms included modifying Windows shell autorun behavior when privileges allowed, altering command processor settings so the malware executed with cmd.exe, and malicious registration of a library. Lyposit also supported periodic polling for operator instructions after code submission and could be instructed to redisplay the lock page or remove itself after successful verification. Reported operator-facing features and related advertisements for closely linked locker variants claimed additional stealth and resilience measures such as process injection, memory-only loading, encrypted bot-server communications, and techniques intended to hinder removal.
Lyposit primarily targeted Windows users in mass monetization campaigns and appears to have focused heavily on victims in the United States and Europe. Its operational model, regional customization, and integration with exploit-kit and botnet distribution channels place it within the early 2010s ecosystem of affiliate-operated police-style locker ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The resulting file is extracted to a temporary folder, and you are running a shell script ... Script within the page should perform basic validation code entered ... run its output through javascript: alert();
writes to the parameter section Shell ... ensure autorun both in normal and safe mode ... with sufficient privileges ... the failure of the right of the recording available in section
bot-server communications are protected/encrypted(test IP hasn't been blacklisted even after testing with 50K+ bots). Not using any standard schemes to send codes to the panel(our own 'Know How').
+++ process injection, the locker is using variety of method to attach itself to the system - from simple to most sofisticated ones.
Operator through the admin interface can give the command to re-display the page with incorrect data, either on samoudalenie if the test data was successfull.
In the absence of a file, it runs a query from the control panel through the BITS technology and Wininet, that allows you to bypass some of the security software.
In any case, the additional auto settings by modifying the shell (no special privileges) As a result, when you start a shell in the normal course of the installation / removal of software, by auto
Some C&C Call : Lyposit.A: windowsonlypositives .org GET /ad/?eaisx=Somebase64encodedData ... Lyposit.B : neufbem9jefnike .com GET /ad/?ck=Somebase64encodedData
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage malware family whose final payload is a lockscreen trojan. It uses a sophisticated loader, decrypts multiple layers in memory, persists via registry changes and command processor extension registration, and communicates with C2 servers over BITS to retrieve location-specific ransom/lockscreen content.
A police-style locker/ransomware family marketed as 'Bomba Locker' and also referred to as Lyposit/Lucky Locker. The content describes lock-screen behavior, country-specific designs, encrypted bot-server communications, memory-only loading, process injection, UAC bypass on Vista/Windows 7, HDD miniport driver replacement, sector-level data hiding/replacement, and strong AV/firewall evasion to make removal difficult and monetize infected users.
A screen-locking ransomware/locker that modifies Windows autorun behavior, including Safe Mode persistence, downloads region-specific lock-screen pages from its control panel via BITS/WinINet, alters the OS color scheme and UI to hinder access, captures and submits entered unlock/payment codes to a server, and can be instructed by operators to relock or self-delete.
Ransomware mentioned as an example of payloads pushed to already infected computers through botnet tasking.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.