LockScreen is a ransom-screen component used in the StopAndProtect cybercrime operation, a modular intrusion set that combines covert data theft, lateral propagation, and selective ransomware activity. The component’s role is to block user input and present a ransom message that includes a payment QR code, functioning as the victim-facing extortion interface after other stages of the intrusion have been deployed. It is not a standalone family in the available reporting, but one module within a broader multi-stage toolkit that also includes .NET downloaders and loaders, the SilentEncryptor ransomware component, the SilentDataCollector stealer, propagation tools for SMB shares, USB devices, removable media, and a custom victim-operator chat utility.
The broader infection chain associated with LockScreen begins with ClickFix-style fake CAPTCHA social engineering hosted on compromised WordPress sites. Victims are tricked into executing PowerShell commands, which launch staged PowerShell and .NET payloads in memory before deploying the final component set. Within that framework, LockScreen appears in the later stage of execution and is associated with extortion activity rather than initial compromise. The surrounding operation has been observed abusing thousands of hacked WordPress sites for malware hosting, command-and-control, and storage of stolen victim data, and has affected victims globally, including significant concentrations in the United States, Russia, and India.
High-confidence reporting supports LockScreen’s use for user-interface denial and ransom-note display. Other capabilities such as encryption, data theft, keylogging, or propagation are attributable to other StopAndProtect modules rather than to LockScreen itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Locker component that blocks user input and displays a ransom message with a payment QR code.
Locker component that blocks user input and presents a ransom note with a payment QR code.
Screen-locking component that blocks user interaction and presents ransom/payment instructions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.