WastedLocker is a Windows ransomware family first observed in May 2020 and attributed to Evil Corp, also known as Indrik Spider. It is deployed in targeted, human-operated intrusions against enterprises, predominantly in the United States. Targets have included professional and legal services, energy, manufacturing, retail, technology, engineering, life sciences, and transportation organizations. Operators prioritize business-critical systems and backup infrastructure to maximize disruption and ransom leverage.
WastedLocker attack chains commonly begin with SocGholish fake software updates distributed through compromised websites. SocGholish establishes initial access and delivers Cobalt Strike, which operators use alongside Windows Management Instrumentation and PsExec for reconnaissance, lateral movement, and subsequent ransomware deployment. These preparatory activities are distinct from the ransomware payload's own functionality.
The ransomware enumerates accessible drives and encrypts files on fixed, removable, shared, and remote storage. Each file receives a newly generated AES-256-CBC key and initialization vector, protected with an embedded RSA-4096 public key. Large files are processed in blocks, while selected directories and file types are excluded. Encrypted files receive victim-specific naming changes and individual ransom notes containing protected key material.
WastedLocker can bypass User Account Control through DLL hijacking, conceal and execute its payload using NTFS alternate data streams, install itself as a Windows service, and modify registry settings associated with access to remote drives. It also deletes shadow copies and volume snapshots and attempts to disable Windows Defender monitoring. Samples have been protected with the CryptOne crypter, which uses multistage decryption and anti-analysis checks. Hades is a later variant with substantial WastedLocker code overlap.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
EvilCorp decided to rename their ransomware operations, so sanctions could no longer be applied. Some of the ransomware names used are WastedLocker, Hades, and Phoenix.
WastedLocker — A ransomware family that has been used against a variety of targets worldwide.
"...shifted to using ransomware variants such as WastedLocker..."
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Additional tools are used to manipulate the file system and suppress any requests for user input and/or confirmation. For example, choice.exe is leveraged to set file attributes as well as delete files. | PowerShell and WMIC are also sometimes utilized in profiling and tuning the environment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
Once executed, the HTA or JS file acts as a preliminary loader, collecting system information and performing anti-analysis checks before using cmd.exe or Powershell.exe to connect to a command and control server to retrieve any secondary payloads for deployment.
This process allows for the ransomware to copy itself into the file by way of an alternate data stream (ADS). | MITRE ATT&CK Hide Artifacts: Hidden Files and Directories T1564
53 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family explicitly linked in the content as associated with SocGholish activity.
Ransomware operation attributed in the article to Evil Corp.
A ransomware family deployed in post-SocGholish intrusion activity and explicitly attributed in the content to EvilCorp.
WastedLocker is a ransomware family described as a downstream payload/customer relationship tied to SocGholish access sales.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.