TorrentLocker is a Windows ransomware family active in the mid-2010s that encrypts victims’ documents and extorts payment in Bitcoin through Tor-hosted payment infrastructure. It became widely known for campaigns that impersonated postal and parcel-delivery services, using spam messages that directed victims to phishing pages presenting fake package-tracking content and prompting download of an archive containing the malware. Campaign operators used geographic filtering so that only users from targeted countries were shown the malicious landing pages, while others were redirected elsewhere. TorrentLocker was first observed targeting Australia and later expanded to the United Kingdom using Royal Mail-themed lures.
Once executed, TorrentLocker encrypts files on the victim system and displays a time-limited ransom demand, increasing the requested payment after the initial deadline. The family is unrelated to the original CryptoLocker despite frequent branding overlap in victim-facing messages, and many infections claiming to be CryptoLocker during that period were in fact TorrentLocker. The malware has also been noted for storing configuration data under a Windows registry location whose name inspired the family’s label.
TorrentLocker has been associated with self-signed SSL/TLS certificates in command-and-control communications, reflecting broader efforts by operators to protect or blend malicious traffic. It has also been referenced in the wider ransomware ecosystem as a payload distributed by other malware, including early Nymaim activity, and it was sufficiently similar in presentation to influence early comparisons with CryptoFortress. The family primarily targeted Windows users through socially engineered delivery and was part of the broader wave of financially motivated ransomware that became prominent before later families such as Cerber and Locky displaced it in prevalence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
I was hunting for Gootkit (pushed in a Nuclear Pack instance in France those days) but instead I got a Teerac.A new crypto ransomware. Nuclear Pack pushing CryptoFortress via CVE-2013-2551
Over the last six years there has been an increased shift by malware authors to secure their C&C communications using the SSL/TLS protocol to stymie detection and blend in with normal traffic.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
TorrentLocker is referenced as the ransomware payload distributed by early Nymaim infections.
A ransomware family referenced as having been widespread in 2016 but no longer in the top 20 by 2017.
Named as an example of ransomware with associated payment-site infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.