Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cyble Research and Intelligence Labs (CRIL) came across a new version of the HexaLocker ransomware. Upon execution, it copies itself to the %appdata% directory, creates a run entry for persistence, encrypts files, and appends the “HexaLockerv2” extension to them. Prior to encryption, the ransomware also steals the victim’s files and exfiltrates them to a remote server.
HexaLocker is a ransomware family that first appeared in July 2024.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
These include: ... Advanced obfuscations (crypting/packing)
These include: ... Improved process-injection Remote Thread Hijacking
On October 2, 2024, HexaLocker posted an update asking for help but also teasing new features in the pipeline. These include: ... Self-deletion
Anti-analysis (anti-VM, anti-debugging): Uses an open-source Golang module called GoDefender2. The following mechanisms are used: Anti-Virtualization: Detecting USB drives. Checking for default virtualization usernames... Checking for default virtualization video controllers... Detecting VM artifacts (VMware and VirtualBox drivers or guest tools).
Anti-Debug: Detecting common hooked functions used for anti-anti-debugging (e.g., CheckRemoteDebuggerPresent, GetTickCount, etc.). Checking for blacklisted window names (e.g., IDA, ILSpy, Fiddler, x32dbg, etc.). Using the classic IsDebuggerPresent and CheckRemoteDebuggerPresent routines.
Anti-analysis (anti-VM, anti-debugging): Uses an open-source Golang module called GoDefender2. The following mechanisms are used: Anti-Virtualization: Detecting USB drives. Checking for default virtualization usernames... Checking for default virtualization video controllers... Detecting VM artifacts (VMware and VirtualBox drivers or guest tools).
Anti-Debug: Detecting common hooked functions used for anti-anti-debugging (e.g., CheckRemoteDebuggerPresent, GetTickCount, etc.). Checking for blacklisted window names (e.g., IDA, ILSpy, Fiddler, x32dbg, etc.). Using the classic IsDebuggerPresent and CheckRemoteDebuggerPresent routines.
Before encryption starts, decryption keys are AES-encrypted with a hardcoded key and sent to a remote HTTPS server via GET method parameters... The HTTP request is sent to https://darkslategray-baboon-853641.hostingersite[.]com/index.php, and the information is stored in the GET parameters.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Golang-based Windows ransomware family closely associated with LAPSUS$, promoted by CyberVolk, with ongoing development focused on anti-analysis, obfuscation, EDR/AV killing, AMSI bypass, process injection, UAC bypass, and self-deletion.
Windows-based Go ransomware that establishes persistence via a Run registry key, exfiltrates victim files before encryption for double extortion, encrypts files with ChaCha20, uses AES-GCM for string obfuscation and Argon2 for key derivation, and appends the .HexaLockerV2 extension to encrypted files.
Windows Golang ransomware that encrypts files under C:\Users using AES-256-GCM with a random password derived via Argon2ID, appends the .hexalocker extension, sends encrypted key material and host info to a remote HTTPS server, drops a ransom note, and also steals selected encrypted user files by zipping and exfiltrating them.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.