Researchers reported that LokiLocker is a relatively new ransomware-as-a-service family targeting Microsoft Windows systems through a small, vetted affiliate network, with activity observed across Eastern Europe, Asia, and English-speaking victims. The malware, first seen in the wild in 2021, encrypts files using AES with RSA-protected keys, demands payment by email, and is written in .NET with NETGuard and the KoiVM virtualization plugin to complicate reverse engineering. Early infections were linked in some cases to trojanized brute-checker tools, and no free decryptor was available.
BlackBerry researchers said the operation may be using false-flag indicators to obscure attribution, citing Iranian-linked clues such as affiliate usernames, cracking tools associated with the AccountCrack team, and an Iran exclusion list in code, while cautioning that the true origin remains unclear. LokiLocker is also notable for a configurable wiper function that can delete non-system files, overwrite the Master Boot Record (MBR), and force a Blue Screen of Death if victims refuse to pay, increasing the risk of destructive impact beyond conventional ransomware encryption.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC reported LokiLocker being distributed in Korea and said the ransomware was highly similar to BlackBit, with unpacked BlackBit samples indicating BlackBit was derived from LokiLocker. The report also published additional technical details on LokiLocker behavior and detection signatures.
BlackBerry reported that the LokiLocker ransomware family was first seen in the wild in mid-August 2021. Researchers described it as a Windows-targeting ransomware-as-a-service operation.
BlackBerry said LokiLocker contained Iranian-linked artifacts, including affiliate usernames seen on Iranian hacking channels, AccountCrack-associated tooling, and an Iran exclusion list in code. The researchers cautioned that these indicators could be false flags and that the malware's true origin remained unclear.
BlackBerry researchers reported that LokiLocker operated through a small vetted affiliate network of about 30 affiliates and included a configurable wiper that could delete non-system files if victims did not pay. They also noted anti-analysis protections such as NETGuard and KoiVM and said no free decryptor was available.
Researchers said early LokiLocker samples were distributed inside trojanized brute-checker hacking tools, including tools tied to the Iranian cracking team AccountCrack. BlackBerry suggested this may have reflected a beta-testing phase before broader affiliate use.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
blogs.blackberry.com
Open sourceasec.ahnlab.com
Open sourcemsspalert.com
Open sourcetheregister.com
Open sourceus-cert.cisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.