Astro Locker is a Windows ransomware family associated with the Astro Locker Team and linked by multiple investigations to the Mount Locker operation, possibly as a rebrand, affiliate relationship, or expansion of that ecosystem. It is used in double-extortion intrusions in which attackers steal data before encrypting systems and then threaten public release of the stolen information to pressure victims into payment. Observed victim notification and negotiation practices include direct outreach and operation of a dedicated leak site for extortion.
The malware has been observed as a 64-bit DLL executed manually by operators through Rundll32, indicating hands-on deployment during late-stage intrusion activity rather than indiscriminate self-propagation. It supports command-line options consistent with operator-driven execution, creates a mutex derived from the victim system to avoid duplicate execution, and writes runtime logs during operation. Before encryption, it terminates selected processes and services, including database-related applications, to maximize file access and encryption coverage. It also excludes selected files, folders, and extensions to avoid disrupting critical system functionality and attacker communication artifacts.
For encryption, Astro Locker uses ChaCha20 with a randomly generated symmetric key that is then encrypted with an embedded RSA public key and appended to encrypted files. Reported analysis indicates that one common symmetric key may be reused across files within a single encryption run. A distinctive behavior is modification of Windows file-association settings so that opening an encrypted file launches the HTML ransom instructions. After completing encryption, the malware creates a self-deletion mechanism and removes its own executable component.
Intrusions associated with Astro Locker have been tied to compromised remote desktop access and credential abuse, and the broader tradecraft overlaps substantially with Mount Locker, including service-based command execution and scheduled-task use. The malware has targeted enterprise environments and is relevant to defenders investigating human-operated ransomware attacks against Windows networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
比較的新しい「アストロチーム」(以降、Astro Locker Teamと記載) という攻撃グループが用いるランサムウェアであるAstro Lockerの挙動について簡単に触れておきましょう。
7 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family discussed in relation to similarities with Mount Locker.
A ransomware brand/team linked in the ransom-note workflow and leak site analysis. Sophos found that Astro Locker victims overlapped with Mount Locker victims and concluded the connection is clearer because both use Mount Locker ransomware, the same ransom note, and shared TTPs.
Ransomware delivered as a 64-bit DLL and manually executed via Rundll32. It creates a mutex to avoid reinfection, writes execution logs, terminates processes and services including many database-related ones, encrypts files using ChaCha20 with a randomly generated symmetric key that is then encrypted with an embedded RSA public key, appends encrypted key material to files, sets registry associations so encrypted files open the ransom note HTML when double-clicked, and deletes itself via a batch file after encryption. It is used in double-extortion attacks, with victims threatened that stolen data will be published on a leak site if they do not pay.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.