MorLock is a threat actor associated with ransomware campaigns targeting Russian organizations. Its toolkit includes LockBit 3.0 and Babuk ransomware, XenAllPasswordPro for credential harvesting, SoftPerfect Network Scanner and PingCastle for network and Active Directory reconnaissance, and resocks for proxy-based remote access. Its operations have used Surfshark VPN and VDSina-hosted infrastructure. MorLock exhibits technical and infrastructure overlaps with Crypt Ghouls, including shared ransomware families, credential-harvesting tools, proxy utilities, and similar tool-deployment naming conventions. These overlaps do not establish that the two are the same actor. MorLock's country of origin, organizational structure, and dominant motivation are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Group targeting Russia with a toolkit and infrastructure overlapping heavily with Crypt Ghouls, including shared utilities, ransomware families, naming conventions, and VPN/hosting providers.
Referenced as a related ransomware intrusion cluster with overlapping tooling, naming conventions, and infrastructure with Crypt Ghouls, suggesting possible resource sharing or collaboration.
Referenced as a separate group conducting similar recent campaigns targeting Russia with overlapping tools/infrastructure; no additional details provided in the content.
Mentioned as a pro-Ukrainian group with a political dimension, providing a comparison with Masque. No specific operations, tools, or vulnerabilities are attributed to MorLock in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.