Security researchers linked WastedLocker to the Evil Corp threat group and reported that the ransomware was being used in targeted intrusions against large U.S. and enterprise victims. The operation followed a big-game hunting model in which attackers sought broad access across corporate networks before launching encryption, aiming to maximize business disruption and ransom pressure rather than relying on opportunistic mass infections.
Investigations found the attackers commonly gained initial access through fake Google Chrome updates delivered via compromised websites, then used post-compromise tooling including Cobalt Strike, Mimikatz, Empire, PowerSploit, PsExec, WMI, and living-off-the-land binaries such as msbuild.exe. The operators conducted manual reconnaissance, stole credentials from SAM and SYSTEM hives, executed remote PowerShell, abused administrative shares and service execution for lateral movement, cleared event logs, attempted to disable protections such as Windows Defender, Symantec Endpoint Protection, and Cisco AMP for Endpoints, and in some cases created local administrator accounts and captured screenshots before deploying the ransomware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Unit 42 reported a recent increase in WastedLocker activity and said the ransomware was primarily targeting U.S.-based organizations with substantial assets across sectors including legal services, utilities, manufacturing, retail, high tech, pharma, and transportation. The report also linked the activity to Evil Corp and described a SocGholish-to-Cobalt Strike intrusion chain used before ransomware deployment.
Cisco Talos published an analysis of the WastedLocker operator's post-compromise activity in corporate networks, including fake Chrome update delivery, Cobalt Strike use, credential dumping, lateral movement, defense evasion, persistence, and screenshot collection. The report characterized the operation as manual, operator-driven ransomware activity aimed at maximizing disruption and ransom pressure.
NCC Group published research describing WastedLocker as a new ransomware variant developed by the Evil Corp group, marking an early public identification of the malware family and its attribution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourceblog.talosintelligence.com
Open sourceblog.fox-it.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourcesymantec-enterprise-blogs.security.com
Open sourceresearch.nccgroup.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.