Investigations into multiple intrusions found Quantum ransomware operators gaining initial access through IcedID and escalating to full ransomware deployment within hours. Reporting links Quantum to the Mount Locker lineage, noting the group also operated under names including Astro Locker and Xing Locker and used a leak site known as Quantum Blog. In one case, defenders observed a progression from IcedID infection to XingLocker ransomware in roughly 24 hours, while other incidents showed the attackers moving from foothold to encryption in less than four hours.
Across the cases, the attackers followed a consistent playbook: reconnaissance with AdFind, Cobalt Strike beacons for command and control, credential theft through LSASS access, lateral movement over RDP, and ransomware deployment via WMI and PsExec. Additional activity included scheduled tasks for persistence and process injection to launch Cobalt Strike. The reporting indicates that the campaign's speed and repeated tradecraft make sequence-based detection of the full attack chain more effective than relying on isolated alerts tied to single tools or commands.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
The DFIR Report published a separate case study focused on a Quantum ransomware intrusion, documenting the group's tactics and attack progression.
The DFIR Report published a case study covering an intrusion in which attackers used IcedID and progressed to XingLocker ransomware within 24 hours.
On 2022-07-06, Anvilogic published an analysis of two Quantum ransomware incidents, concluding that sequence-based detections of attacker behavior are more reliable than isolated alerts. The article highlighted recurring use of IcedID, Cobalt Strike, credential theft, lateral movement, and rapid ransomware deployment.
The Anvilogic analysis states that Quantum ransomware had been discovered by July 2021 and describes it as a rebranding lineage of Mount Locker that also operated as Astro Locker and Xing Locker.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.