WhiteLock ransomware has been identified targeting Windows systems, encrypting files and appending the .Fbin extension before dropping a ransom note named c0ntact.Txt and changing the victim’s wallpaper to increase pressure to pay. During execution, the malware contacts an external server, derives a victim identifier by hashing the device’s MAC address, retrieves an RSA public key, and encrypts files with AES-CBC while protecting the AES key with RSA-2048.
The operation also attempts to hinder containment by checking for AnyDesk and TeamViewer and terminating their services while encryption is underway. The ransom note claims both file encryption and data theft, threatens to publish or sell stolen data if payment is not made, and directs victims to a Tor-based negotiation page. Reporting also links WhiteLock activity to campaigns where information-stealing malware was used for initial access before ransomware deployment, underscoring the need to monitor abnormal outbound connections, remote access tool activity, mass file changes, ransom note creation, and service termination behavior.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC published an analysis describing WhiteLock as a Windows ransomware strain that appends the .Fbin extension, drops a ransom note named c0ntact.Txt, changes the victim wallpaper, contacts an external server for an RSA public key, and terminates AnyDesk and TeamViewer services during encryption. The report also noted ransom-note claims of data theft and links to campaigns where information-stealing malware was used for initial access before ransomware deployment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceasec.ahnlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.