LockerGoga is Windows ransomware used in targeted attacks against enterprise networks, including industrial organizations. It encrypts victim files, including core operating-system files, and demands Bitcoin payment for decryption. Its encryption scheme uses RSA-OAEP with MGF1. LockerGoga can also change account passwords and log off active users, preventing legitimate access and compounding the disruption caused by encryption.
Operators distribute LockerGoga within compromised networks by manually copying its payload over SMB rather than relying on autonomous self-propagation. Its implementation uses parent and child processes to coordinate encryption through shared memory, incorporates native Windows APIs, and can wipe free disk space. LockerGoga has been associated with FIN6 intrusions and attacks against companies in Western Europe and North America. Victims include Norsk Hydro, whose global network suffered significant disruption.
A Swiss court found that a common developer created LockerGoga, MegaCortex, and Nefilim, while distinguishing malware development from the organization of the extortion operations. Bitdefender released a free LockerGoga decryptor in 2022 in cooperation with law enforcement.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
While Atlassian only had one trending vulnerability against Confluence, it was targeted by several families including Gandcrab, Lockergoga, and Megacortex.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Pick-Six: Intercepting a FIN6 Intrusion, an Actor Recently Tied to Ryuk and LockerGoga Ransomware.
The court found the unnamed Ukrainian man to be the lead developer of the LockerGoga, MegaCortex, and Nefilim ransomware families. Bitdefender released a free LockerGoga decryptor in 2022.
Les attaques ont utilisé trois familles de ransomware : LockerGoga, MegaCortex, Nefilim.
L’ANSSI a observé depuis maintenant plusieurs mois des campagnes d’attaques dans lesquelles des rançongiciels nommés « LockerGoga » et « Ryuk » sont déposés sur les systèmes d’information des victimes.
"From mid-2018... FIN6 or affiliated parties were distributing the Ryuk and LockerGoga ransomware"
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Le suspect est présenté comme le principal développeur des rançongiciels Lockergoga, Megacortex et Nefilim; Stadler Rail a été sommée de payer une rançon en bitcoin.
TTPs et IOCs détectés # TTP # T1486 — Data Encrypted for Impact (Impact) T1489 — Service Stop (Impact)
Windows標準ツールである「cipher.exe」を利用して、全てのドライブの空き領域を消去します。これには、フォレンジックによるファイルの復元を困難にさせる目的があると考えられます。
LockerGogaはOS標準ツールである「netsh.exe」を利用して、端末に存在する全てのネットワークインターフェイスを無効にします。
全ての対象ファイルの暗号化が終わると、LockerGoga(マスター)は、OS標準ツールの「logoff.exe」を利用して、自身が動作しているユーザーセッション以外の全てのセッションのログオフを試みます。
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.
153 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
80 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family used to blackmail organizations worldwide by encrypting files; its source code was allegedly developed by the convicted individual. A free decryptor was released in 2022.
Ransomware family mentioned only in passing in relation to an unrelated Swiss criminal sentence.
Ransomware allegedly developed by the convicted suspect; it was used in attacks including those targeting French organizations, and a decryptor was subsequently published following the investigation.
Ransomware family that the convicted developer was found to have developed; the article does not specify its technical functionality beyond ransomware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.