Discovery Enum
- AdFind
- Bloodhound
- PowerView
- ShareFinder
XingLocker is a Windows ransomware family associated with financially motivated intrusion activity and observed in operations where initial access malware such as IcedID was used to rapidly progress from compromise to ransomware deployment.
Profile source: Mallory opens in a new tabXingLocker
XingLocker is a Windows ransomware family associated with financially motivated intrusion activity and observed in operations where initial access malware such as IcedID was used to rapidly progress from compromise to ransomware deployment. It has been linked in reporting to the cybercrime ecosystem around Conti and was later described as having rebranded as Quantum. Activity associated with XingLocker followed the broader big-game hunting ransomware model, in which operators used commodity or brokered access, post-exploitation tooling, and domain-wide intrusion techniques before encrypting victim environments.
Observed tradecraft in incidents involving XingLocker included use of IcedID as an entry point, followed by extensive hands-on-keyboard post-exploitation. Operators used common Windows-native and third-party tooling for discovery, credential access, persistence, and lateral movement. Reported behaviors included credential dumping from LSASS, Active Directory and host discovery, deployment of Cobalt Strike for command and control and follow-on operations, creation of persistence through scheduled tasks and additional accounts, movement across the network via remote administration mechanisms, and attempts to disable endpoint protections. In at least one XingLocker-related intrusion, attackers used scripts derived from publicly available tooling to disable antivirus and EDR defenses before ransomware execution.
XingLocker targeted Windows enterprise environments and fits the pattern of ransomware operations focused on full-domain compromise and high-value organizational impact rather than opportunistic single-host infections. Its operational context places it within the broader ransomware affiliate and initial-access ecosystem that relied on malware loaders, credential theft, lateral movement, and defense evasion to prepare victim networks for encryption and extortion.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.