LockerGoga hit large organizations across the United States and Europe, including reported victims such as Norsk Hydro, Altran, Hexion, and MPM Holdings, while the FBI later warned that the threat overlapped with MegaCortex in targeting enterprise networks. Investigators said the operators typically gained initial access through exploits, phishing, SQL injection, and stolen credentials, then spent weeks or months moving laterally with tools such as Cobalt Strike before encrypting systems. The malware appended the .LOCKED extension, dropped ransom notes such as README_LOCKED.txt, and in some cases was signed with a revoked Sectigo certificate issued to ALISA LTD, likely to reduce detection.
Researchers said LockerGoga blurred the line between ransomware and a wiper because later variants forcibly logged users off Windows systems, blocked them from logging back in, disabled network interfaces, changed local passwords, and could even clear Windows Event Logs and encrypt files in the Recycle Bin. Reporting indicated the malware did not appear to self-propagate, but once attackers had domain access they could disable security tools and deploy it broadly across compromised environments. The FBI urged organizations to maintain offline backups, patch exposed systems, enforce strong passwords and MFA, disable SMBv1, audit remote access and account creation, monitor Active Directory changes, and enable PowerShell logging to detect similar intrusions earlier.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The FBI said LockerGoga had targeted large corporations and organizations in the United States, United Kingdom, France, Norway, and the Netherlands since January 2019.
Cisco Talos reported that a LockerGoga campaign in January used the ransom note filename "README-NOW.txt" instead of the more typical "README_LOCKED.txt."
The FBI issued a Flash Alert warning private industry about LockerGoga and MegaCortex ransomware, describing them as enterprise-focused threats that compromise networks before encrypting devices.
The Center for Internet Security released a primer containing current information and known indicators of compromise for LockerGoga.
Emsisoft released a free decrypter for Aurora ransomware, also known as Zorro, Desu, and AnimusLocker.
F-Secure released a free decryption tool for Mira ransomware victims and said it must be run on the original infected computer after the malware is removed.
Cisco Talos analyzed LockerGoga's behavior, including file encryption, log clearing, lack of self-propagation, and later variants that forcibly logged users off and blocked them from logging back in.
Cisco Talos reported that several LockerGoga samples were signed with a certificate issued to ALISA LTD by Sectigo, and that the certificate was later revoked.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcembsd.jp
Open sourcehelpnetsecurity.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.