LockFile is a ransomware operation first observed in July 2021. It is known for using intermittent encryption, encrypting alternating portions of files rather than only initial blocks, a technique designed to hinder statistical and behavior-based ransomware detection while still rendering data unusable. The malware has been described as encrypting every alternate 16 bytes of targeted files, leaving some content partially readable while defeating some defensive heuristics. LockFile operators exploited internet-facing Microsoft Exchange Server vulnerabilities in the ProxyShell chain and also abused PetitPotam-related tradecraft to compromise Windows enterprise environments, including domain infrastructure. Reported intrusions involved exploitation of Exchange for initial access, deployment of web shells and follow-on tooling, privilege escalation, and broad ransomware distribution across Active Directory environments. Observed post-compromise activity included PowerShell-based payload retrieval, use of Cobalt Strike, DLL sideloading or search-order hijacking, abuse of legitimate signed binaries, and domain-wide deployment through Group Policy and shared administrative infrastructure. The ransomware terminates processes associated with virtualization platforms and databases, including through WMI, before encrypting files. It enumerates local drives, targets a broad set of enterprise-relevant file types, appends its own extension to encrypted files, displays an HTA-based ransom note, and deletes itself after execution to reduce forensic recovery opportunities. Reporting has also noted stylistic similarities between LockFile ransom messaging and other ransomware families, but such overlaps are insufficient for firm attribution. LockFile activity has been associated with attacks against enterprise Windows server environments and organizations in the United States and Asia. Public reporting has also noted overlaps in tooling discussions involving HUI Loader and actors such as BRONZE RIVERSIDE/APT10, but those overlaps do not establish that LockFile is a nation-state actor. Based on the available facts, LockFile is best characterized as a financially motivated ransomware threat actor focused on enterprise compromise, privilege escalation, defense evasion, and large-scale encryption of victim networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Microsoft Exchange Server Security Feature Bypass Vulnerability (CVE-2021-31207): Certain Microsoft Exchange PowerShell command APIs do not restrict the file path and suffix when writing files, allowing attackers to write arbitrary files... During the process, the vulnerability CVE-2021-31207 is used.
NSFOCUS CERT discovered a slew of security incidents that exploited security vulnerabilities (ProxyShell) in Microsoft Exchange... LockFile took advantage of these ProxyShell and PetitPotam vulnerabilities... Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-34473)... Microsoft Exchange Privilege Escalation Vulnerability (CVE-2021-34523)... Microsoft Exchange Server Security Feature Bypass Vulnerability (CVE-2021-31207). | Microsoft Exchange Server Remote Code Execution Vulnerability (CVE-2021-34473): This vulnerability arises due to the lack of proper validation of access privileges for URIs... The CVE-2021-34473 vulnerability is exploited during the process.
Microsoft Exchange Privilege Escalation Vulnerability (CVE-2021-34523): As Microsoft Exchange Server does not properly validate an access token before executing the Exchange PowerShell command... The vulnerability exploited in the process is CVE-2021-34523.
Windows LSA Spoofing Vulnerability (CVE-2021-36942): An attacker could exploit EFSRPC (Encrypting File System Remote Protocol) to launch an NTLM relay attack dubbed PetitPotam, to escalate their system privileges... The privilege escalation tool EfsPotato exploits the CVE-2021-36942 vulnerability which is also known as PetitPotam.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the ransomware family Atom Silo closely resembles, and as a comparison point for similar techniques seen in prior attacks.
Mentioned as one of several ransomware groups that have used ProxyShell exploits.
Conducting ransomware attacks against enterprise domain environments by exploiting Microsoft Exchange ProxyShell and Windows PetitPotam vulnerabilities, planting web shells, deploying Cobalt Strike via DLL hijacking, escalating privileges, and distributing ransomware through Active Directory Group Policy.
A ransomware operation using intermittent encryption to evade ransomware defenses, exploiting ProxyShell and PetitPotam to compromise Windows servers, terminate processes via WMI, encrypt files, and delete itself after execution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.