Skip to content

MountLocker

MountLocker is a Windows ransomware family first observed in 2020 and associated in some reporting with the XingLocker ransomware group.

Profile source: Mallory opens in a new tab

MountLocker

Family profile

MountLocker is a Windows ransomware family first observed in 2020 and associated in some reporting with the XingLocker ransomware group. It encrypts victim files using a hybrid scheme combining ChaCha20 and RSA-2048, writes ransom notes, profiles the infected host, and can delete itself after execution. MountLocker has also been linked to double-extortion activity in which operators steal unencrypted data and threaten publication to pressure victims into paying.

The malware supports extensive command-line control over its operation. Before encryption it can collect host details such as operating system version, architecture, memory, processor count, user and computer context, and domain status. It enumerates local drives, mapped drives, and network shares, recursively traverses directories, skips selected system paths and file types, and drops ransom notes in affected folders. It also attempts to maximize file access by terminating services and processes associated with databases, email, office applications, and some analysis tools.

A notable capability in later variants is worm-like lateral movement across Windows networks. MountLocker can enumerate domain computers through Active Directory and LDAP-related APIs, authenticate to remote systems with supplied credentials, copy itself to administrative or other writable shares, and execute remotely either by creating a temporary Windows service or through WMI. Reporting also notes use of Active Directory queries to identify systems in the domain, making the malware capable of automated propagation inside enterprise environments.

MountLocker has been observed in enterprise ransomware incidents, including attacks against corporate victims, and has appeared in reporting on financially motivated intrusion ecosystems. It has been mentioned in connection with access-broker activity in which third parties likely provided network access to MountLocker operators. Industries specifically targeted are not consistently exclusive, but the malware has been part of broader big-game hunting and extortion operations affecting organizations in multiple sectors.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Extortion
  • Lateral Movement
  • Reconnaissance

Operational record

1
YARA rules
1
Leak sites
0 available

Exfiltration

  • MEGA
  • PrivatLab

Reported operators

Threat actors

1 named in public reporting
ToyMaker

Prophet Spider functioned as an access broker and likely granted access to Egregor and MountLocker ransomware operators in exchange for payment.

Exploited software

Vulnerabilities linked to MountLocker

2 CVEs

MITRE ATT&CK

MountLocker in ATT&CK

29 distinct techniques

Reporting

Research mentioning MountLocker

Jan 1
Sophos Threat Research

Sophos MTR in Real Time: What is Astro Locker Team? | SOPHOS

Mount Locker emerged as a corporate-targeting ransomware operation that stole data before encrypting files and then demanded multi-million dollar payments while threatening to leak stolen information on a Tor-hosted extortion site. Reporting on early victims said the group had already listed multiple organizations on its leak portal and published at least one victim’s files after nonpayment. The malware used ChaCha20 for file encryption and an embedded RSA-2048 public key to protect encryption material, dropped a ransom note named RecoveryManual.html, and appended a .ReadManual.ID-style extension to encrypted files. Reverse-engineering of Mount Locker samples and later variants showed the ransomware also included operational features for enterprise-wide impact, including command-line options for targeting hosts, suppressing logs, avoiding process termination controls, and encrypting network resources. Analysts reported that newer builds added worm-like lateral movement by enumerating domain or network systems, requiring /LOGIN= and /PASSWORD= parameters for propagation, copying itself to remote machines, creating services named in an Update{GetTickCount()} pattern, and in some cases launching remotely through WMI under ROOT\CIMV2. The malware was also described as killing selected services and processes before encryption to maximize disruption.

Aug 4
Kienmanowar

[QuickNote] MountLocker - Some pseudo-code snippets | 0day in {REA_TEAM}

Jun 20
Github Web

Malware-Analysis-Reports/MountLocker at master · Finch4/Malware-Analysis-Reports · GitHub

May 23
Chuongdong

MountLocker Ransomware | Chuong Dong

Nov 19
Bleeping Computer

Mount Locker ransomware now targets your TurboTax tax returns

Sep 24
Bleeping Computer

Mount Locker ransomware joins the multi-million dollar ransom game

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.