LokiLocker is a Windows ransomware family operated as a ransomware-as-a-service offering since at least August 2021. It is distinct from the older Locky ransomware and from the LokiBot infostealer. The malware has been observed targeting victims globally, with reporting indicating notable activity in Eastern Europe and Asia and confirmed distribution in Korea. It has been described as a limited-access affiliate operation with a relatively small number of vetted partners, suggesting an early-stage or beta-era RaaS model.
LokiLocker encrypts data on local drives and network shares using AES, with RSA used to protect encryption keys, and then demands payment for recovery instructions. In addition to standard ransomware behavior, it is notable for built-in destructive functionality: configurable wiping logic can delete non-system files if payment is not made, and some observed variants attempt to overwrite the master boot record and force a system crash, rendering the host unusable. The malware has also been reported deleting volume shadow copies to hinder restoration and recovery.
The family is implemented in .NET and uses obfuscation and anti-analysis protections including NETGuard, described as a modified ConfuserEX, as well as the KoiVM virtualization plugin. Separate reporting has also associated LokiLocker samples with .NET Reactor obfuscation. Observed persistence mechanisms include scheduled tasks and registry-based persistence. Researchers have also noted behavior intended to obstruct detection and support information leakage or extortion pressure.
Early distribution has been linked to trojanized brute-checker and account-validation tools used in credential-stuffing ecosystems, indicating a criminal distribution channel tied to compromised-account abuse rather than broad indiscriminate spam. Attribution remains uncertain. Some reporting has highlighted possible Iranian links based on affiliate usernames, tooling associations, and an Iran-related exclusion artifact in code, but these indicators have also been assessed as potentially deliberate false flags. LokiLocker has additionally been assessed as highly similar to BlackBit, with some analysis suggesting BlackBit was derived from LokiLocker.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A relatively new ransomware-as-a-service (RaaS) family known as LokiLocker is targeting Microsoft Windows users globally through a small, distributed network of affiliates... The bug enters the victim’s network, encrypts files, and demands a monetary ransom to restore access.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The following figure shows that the LokiLocker ransomware registers itself to the task scheduler and registry under the name”Loki” before it starts its encryption process.
The following figure shows that the LokiLocker ransomware registers itself to the task scheduler and registry under the name”Loki” before it starts its encryption process.
The ransomware creates a Task Scheduler for the " winlogon.exe " file to ensure it is able to execute each time a user logs into the system for persistence.
the malware creates a batch file that contains a code of registry modification to disable the task manager.
The following figure shows that the LokiLocker ransomware registers itself to the task scheduler and registry under the name”Loki” before it starts its encryption process.
The ransomware creates a Task Scheduler for the " winlogon.exe " file to ensure it is able to execute each time a user logs into the system for persistence.
The malware is written in .NET and protected with NETGuard ... while also using KoiVM, a virtualization plugin. The use of KoiVM as a protector is an unusual method for complicating analysis of the malware...
The malware... may have the ability to display a false flag tactic that blames Iranian actors... it's not clear if the bug actually originates from Iran or the authors are trying to feint tracking.
Afterward, it carries out actions such as deleting volume shadows to prevent recovery, as well as behaviors aimed at obstructing detection and leaking information.
the malware initiates by retrieving a comprehensive list of all services running on the system.
The ransomware proceeds with the next activity, terminating several processes... The ransomware enumerates all running processes
The malware made POST request communication, with information such as unique-id, disk-size, affiliate username, CPU-name, ram-size, and os-name
The ransomware uses a combination of AES for file encryption and RSA for key protection to encrypt documents on victims' local hard drives and network shares.
Once the potentially disruptive services are identified, the malware takes action by stopping the services.
In addition, after overwriting the MBR, the ransomware will try to crash the system by forcing a Blue Screen of Death.
the ransomware changes the compromised host's wallpaper background, replacing it with their custom wallpaper.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware distributed in Korea that disguises itself as svchost.exe, uses .NET Reactor obfuscation, establishes persistence via task scheduler and registry entries, creates ransom notes, encrypts files, deletes volume shadow copies to hinder recovery, and performs anti-detection and information-leaking behaviors.
Ransomware-as-a-service family targeting Windows systems. It encrypts files on local drives and network shares using AES with RSA key protection, demands ransom payment instructions via email, and also includes wiper functionality to delete non-system files if victims refuse to pay.
LokiLocker ransomware family spotted with built-in wiper
A ransomware-as-a-service family targeting Windows systems that encrypts files on local drives and network shares using AES with RSA-protected keys, demands ransom via email, and can escalate to wiping non-system files, overwriting the MBR, and forcing a Blue Screen of Death if payment is not made.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.