ColdLock is a ransomware family observed in targeted intrusions against Taiwanese organizations, including state-owned industrial and energy-sector entities. It is considered potentially destructive because it has been used to encrypt databases and email servers, indicating an intent to disrupt core business and operational services rather than only end-user files. Reporting has linked ColdLock activity to compromises in Taiwan and to broader victimology in Southeast Asia spanning energy, retail, and telecommunications.
ColdLock has been associated with hands-on-keyboard post-compromise operations rather than indiscriminate mass distribution. In documented incidents, attackers obtained valid Active Directory credentials, modified Group Policy Objects to create scheduled tasks, and propagated execution across domain-joined systems. Lateral movement and deployment leveraged SMB, PowerShell, and customized loader components installed as Windows services, with those loaders decrypting and launching follow-on payloads. Related intrusions also involved credential dumping and HTTP tunneling prior to ransomware deployment, and Cobalt Strike was used as a next-stage payload in affected environments. Reflective DLL injection has also been reported as a deployment technique for ColdLock.
The malware has been discussed in connection with Chinese state-linked activity. Trend Micro linked ColdLock attacks on Taiwanese organizations to APT41-related operations, while Dragos assessed with low confidence that VANADINITE may have been responsible for a ColdLock incident affecting Taiwanese state-owned ICS companies and indirectly disrupting operations. The available reporting supports a nexus to espionage-oriented or strategically targeted intrusions, but attribution remains qualified rather than definitive.
ColdLock runs in Windows environments and has been used against enterprise networks that support critical services, including industrial organizations. Its operational profile reflects ransomware used as the disruptive end stage of a broader intrusion involving credential abuse, domain-wide tasking, service-based persistence, and staged payload execution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The new ransomware family, which we dubbed ColdLock, is potentially destructive as it appears to target databases and email servers for encryption.
Dragos assesses with low confidence VANADINITE is responsible for the ColdLock ransomware attack that targeted Taiwanese state-owned ICS companies and caused indirect disruption to operations.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Scheduled tasks play a very important role in this incident. The threat actors use a scheduled task command to spread and infect a victim's environment.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a ransomware case cited in discussion of possible state involvement in cyber operations.
A ransomware family linked in the article to APT41 activity against Taiwanese organizations. It encrypts databases and email servers, is deployed broadly via Active Directory scheduled tasks, and uses a main loader file ('lc.tmp') copied over SMB/internal IIS before execution.
Ransomware previously deployed via reflective DLL loading and described as targeting Taiwanese organizations, especially databases and email servers.
Ransomware linked with low confidence to VANADINITE; targeted Taiwanese state-owned ICS companies and indirectly disrupted operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.