A newly identified Chinese ransomware strain, DexCrypt MBRLocker (also referred to as DexLocker), was reported replacing victims’ master boot record (MBR) and locking systems before Windows could start. After infection, affected machines reportedly rebooted immediately into a pre-boot ransom screen featuring an ASCII skull and instructions to send 30 Yuan to QQ account 2055965068 to regain access. Microsoft said Windows Defender detects the malware as Ransom:DOS/Dexcrypt.A, and an Any.Run analysis showed the reboot-and-lock behavior occurring directly after execution.
The report said some victims may be able to unlock the system with the password ssssss, while recovery is also possible in cases where only the MBR was overwritten. In those situations, responders can use the Windows Recovery Console to repair the boot record with commands such as:
bootrec /fixmbr
bootrec /fixboot

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
Researcher kangxiaopao stated that entering the password "ssssss" may restore access on affected systems. The report also noted that if only the MBR was replaced, recovery may be possible through the Windows Recovery Console using bootrec commands.
Microsoft's Windows Defender Security Team said the malware is detected as Ransom:DOS/Dexcrypt.A, indicating Defender can identify the threat.
An AnyRun video posted by JAMESWT showed DexLocker immediately rebooting an infected computer after installation and displaying a pre-boot lock screen with an ASCII skull. The ransom note demanded 30 Yuan be sent to QQ account 2055965068.
Security researcher JAMESWT first discovered the Chinese MBRLocker ransomware family DexLocker, which overwrites the master boot record and locks systems before Windows starts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.