Lilocked, also known as Lilu, is a Linux-targeting ransomware family observed in 2019 that primarily affected internet-exposed web servers and website-hosting environments. It encrypts victim files, appends a distinctive additional extension to affected data, and drops ransom notes in encrypted directories directing victims to a Tor-based payment portal. Reported targeting centered on website content and server-side data, with impacted systems including Linux servers used for web hosting.
The malware is associated with file encryption of common website and server data, including documents, databases, images, archives, and other business-relevant content. Public reporting described the ransomware as using AES for file encryption and, in some cases, deleting itself after completing encryption. At the time it was documented, no public decryption method was known.
Observed ransom operations used per-victim access keys and relatively low cryptocurrency demands compared with many enterprise ransomware campaigns. The campaign became notable because encrypted website files on compromised servers were indexed by search engines, making infections unusually visible at scale.
Initial access has not been conclusively established. Victim reporting and researcher commentary suggested possible compromise through vulnerable server software or outdated web applications, including web-hosting components and content-management systems, but these vectors were not independently confirmed at high confidence. More speculative claims that it spread through broad channels such as spam, malicious attachments, exposed remote administration, malvertising, fake updates, or trojanized installers are not well corroborated for this family and should be treated cautiously.
Lilocked is best characterized as Linux server ransomware focused on web-facing environments rather than a mass-market desktop threat. Its known behavior centers on encrypting server-hosted content and extorting victims for payment in exchange for decryption.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Может распространяться путём взлома через незащищенную конфигурацию RDP...
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux ransomware that encrypts data on websites and servers using AES, appends the .lilocked extension, drops the ransom note #README.lilocked, and demands Bitcoin payment via a Tor-based payment site for decryption.
Referenced as a past example of Linux ransomware/malware.
Ransomware targeting servers, particularly compromised web servers, encrypting files and appending the .lilocked extension. It drops a ransom note named #README.lilocked in encrypted folders and directs victims to a Tor payment site to pay approximately 0.010 BTC for decryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.