Mount Locker emerged as a corporate-targeting ransomware operation that stole data before encrypting files and then demanded multi-million dollar payments while threatening to leak stolen information on a Tor-hosted extortion site. Reporting on early victims said the group had already listed multiple organizations on its leak portal and published at least one victim’s files after nonpayment. The malware used ChaCha20 for file encryption and an embedded RSA-2048 public key to protect encryption material, dropped a ransom note named RecoveryManual.html, and appended a .ReadManual.ID-style extension to encrypted files.
Reverse-engineering of Mount Locker samples and later variants showed the ransomware also included operational features for enterprise-wide impact, including command-line options for targeting hosts, suppressing logs, avoiding process termination controls, and encrypting network resources. Analysts reported that newer builds added worm-like lateral movement by enumerating domain or network systems, requiring /LOGIN= and /PASSWORD= parameters for propagation, copying itself to remote machines, creating services named in an Update{GetTickCount()} pattern, and in some cases launching remotely through WMI under ROOT\CIMV2. The malware was also described as killing selected services and processes before encryption to maximize disruption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Sophos reported that an investigated intrusion initially identified as Mount Locker was closely tied to Astro Locker, with the ransom note's Tor contact identifying itself as Astro Locker Team. Sophos found all five victims on the Astro Locker leak site also appeared on Mount Locker's leak site with matching leak sizes and overlapping data links, and assessed the groups may be affiliated, rebranding, or expanding into ransomware-as-a-service.
A new Mount Locker version was reported to specifically encrypt TurboTax-associated file extensions including .tax, .tax2009, .tax2013, and .tax2014. Analysis cited by BleepingComputer said the matching logic could broadly affect extensions containing the string "tax."
Mount Locker was reported as targeting corporate networks by the end of July 2020. The operation stole data before encrypting files and used leak threats to pressure victims into paying large ransoms.
A later Mount Locker update was described as adding worm functionality that could enumerate domain or network systems and spread using supplied credentials. The analysis said it could drop itself remotely, create Update{GetTickCount()} services, and also use WMI for execution.
MalwareHunterTeam discovered a Mount Locker sample and Michael Gillespie analyzed it, reporting that it used ChaCha20 with an embedded RSA-2048 public key. The sample appended .ReadManual.ID-style extensions and used a RecoveryManual.html note directing victims to a Tor negotiation site.
At least one victim that refused to pay had its stolen files published on Mount Locker's leak site. At the time of reporting, the leak site listed four victims and one had already been exposed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcekienmanowar.wordpress.com
Open sourcegithub.com
Open sourcechuongdong.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.