Ransomware Group intelligence
Chilelocker
ActiveTrack Chilelocker with 0 published victims and 1 known leak locations in a single intelligence view.
Overview
Chilelocker is tracked by Breach House as a ransomware group with 0 published victims.
The group is tracked across multiple victim records in the Breach House dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 8h ago | z6vidveub2ypo3d3x7omsmcxqwxkkmvn5y3paoufyd2tt4bfbkg33kid.onion |
Top Activity Sectors
No sector intelligence available.
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Chilelocker, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: chilelocker uses PowerShell scripts to execute malicious commands and payload deployment across compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: chilelocker modifies Registry Run Keys to ensure malware persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: chilelocker disables security tools like antivirus software and monitoring agents to evade detection.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: chilelocker encrypts and encodes its own malware binaries to evade signature-based detection.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: chilelocker deletes Volume Shadow Copies and backup files via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1135 Network Share Discovery Discovery
What they do: chilelocker discovers network shares to identify additional systems for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: chilelocker uses SMB/Windows Admin Shares to spread ransomware across networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1048 Exfiltration Over Alternative Protocol Exfiltration
What they do: chilelocker exfiltrates stolen data using its command-and-control channel before encryption.
What that means: Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
-
T1486 Data Encrypted for Impact Impact
What they do: chilelocker encrypts victim files and data using its ransomware payload to maximize impact and extortion.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: chilelocker runs system recovery inhibitors to block victim attempts to restore compromised environments.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_for_unlock_2.txt
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
HELLO
[snip]
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
----> Attention <----
DO NOT:
->Modify, rename, copy or move any files or you can DAMAGE them and decryption will be impossible
->Use any third-party or public Decryption software, it also may DAMAGE files
->Shutdown or Reset your system, it can DAMAGE files
->Hire any third-party negotiators (recovery/police and etc)
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
Your security perimeter was BREACHED.
Critically important servers and hosts were completely ENCRYPTED.
This README-FILE here for you to show you our presence in your's network and avoid any silence about hacking and leakage.
Also, we has DOWNLOADED about 700GB your MOST SENSITIVE Data just in case if you will NOT PAY,
than everything will be PUBLISHED in Media and/or SOLD to any third-party.
1) WHAT SHOULD YOU DO:
--> You have to contact us as soon as possible (you can find contacts below)
--> You should purchase our decryption tool, so will be able to restore your files. Without our Decryption keys it's impossible
--> You should make a Deal with us, to avoid your Data leakage
2) YOUR OPTIONS:
--> IF NO CONTACT OR DEAL MADE IN 3 DAYS:
Decryption key will be deleted permanently and recovery will be impossible
All your Data will be Published and/or Sold to any third-parties
Information regarding vulnerabilities of your network also can be published and/or shared
--> IF WE MAKE A DEAL:
We will provide you with the Decryption Key and Manual how-to-use
We will remove all your files from our file-storage with proof of Deletion
We guarantee to avoid sharing any details with third-parties
We will provide you the penetration report and list of security-recommendations
3) WE HAS COLLECTED SUCH DATA AS:
--> Confidential files and documents, Passports, HR directories, Employees personal info
--> Detailed company information, Projects, Sales files and reports, Accountant files
--> Financial documents, Commercial info, Internal correspondence
--> Contracts, Agreements, Clients Data
--> Outlook dumps, SQL dumps and a lot of other sensitive data
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
!!!Instructions for contacting our Team!!!
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
--> Download and install TOR browser from this site : https://torproject.org
--> For contact us via LIVE CHAT open our website : http://ebljej7okwfnx5hdfikqqt2uqehihqv3yns3ziij5clqpklwb3i2cxad.onion/r/[snip]
Your password:[snip]
Your username:[snip]
Recovery contact:for[snip][email protected]
--> If Tor is restricted in your area, use VPN
--> All your Data will be published in 5 Days if NO contact made
--> Your Decryption keys will be permanently destroyed in 3 Days if no contact made
--> Your Data will be published if you will hire third-party negotiators to contact us
readme_for_unlock.txt
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
HELLO!
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
----> Attention <----
DO NOT:
--Modify, rename, copy or move any files or you can DAMAGE them and decryption will be impossible.
--Use any third-party or public Decryption software, it also may DAMAGE files.
--Shutdown or Reset your system, it can DAMAGE files.
--Hire any third-party negotiators (recovery/police and etc).
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
Your security perimeter was BREACHED.
Critically important servers and hosts were completely ENCRYPTED.
This README-FILE here for you to show you our presence in your's network and avoid any silence about hacking and leakage.
Also, we has DOWNLOADED your most SENSITIVE Data just in case if you will NOT PAY,
than everything will be PUBLISHED in Media and/or SOLD to any third-party.
1) WHAT SHOULD YOU DO:
---> You have to contact us as soon as possible (you can find contacts below)
---> You should purchase our decryption tool, so will be able to restore your files. Without our Decryption keys it's impossible
---> You should make a Deal with us, to avoid your Data leakage
2) YOUR OPTIONS:
---> IF NO CONTACT OR DEAL MADE IN 3 DAYS:
Decryption key will be deleted permanently and recovery will be impossible.
All your Data will be Published and/or Sold to any third-parties
Information regarding vulnerabilities of your network also can be published and/or shared
---> IF WE MAKE A DEAL:
We will provide you with the Decryption Key and Manual how-to-use.
We will remove all your files from our file-storage with proof of Deletion
We guarantee to avoid sharing any details with third-parties
We will provide you the penetration report and list of security-recommendations
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
!!!!Instructions for contacting our team!!!!
-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-+-
---> Download and install TOR browser from this site : https://torproject.org
---> For contact us via LIVE CHAT open our website : http://z6vidveub2ypo3d3x7omsmcxqwxkkmvn5y3paoufyd2tt4bfbkg33kid.onion
Password:[snip]
---> If Tor is restricted in your area, use VPN
---> All your Data will be published in 3 Days if NO contact made
---> Your Decryption keys will be permanently destroyed in 3 Days if no contact made
---> Your Data will be published if you will hire third-party negotiators to contact us
readme_for_unlock_3.txt
--> ATTENTION <-- DO NOT: Modify, rename, copy or move any files or you can DAMAGE them and decryption will be impossible Use any third-party or public Decryption software, it also may DAMAGE files Shutdown or Reset your system, it can DAMAGE files Hire any third-party negotiators (recovery/police and etc) Your security perimeter was BREACHED Critically important servers and hosts were completely ENCRYPTED This README-FILE here for you to show you our presence in your's network and avoid any silence about hacking and leakage Also, we has DOWNLOADED your most SENSITIVE Data just in case if you will NOT PAY, than everything will be PUBLISHED in Media and/or SOLD to any third-party 1) WHAT SHOULD YOU DO: You have to contact us as soon as possible (you can find contacts below) You should purchase our decryption tool, so will be able to restore your files Without our Decryption keys it's impossible You should make a Deal with us, to avoid your Data leakage 2) YOUR OPTIONS: IF NO CONTACT OR DEAL MADE IN 3 DAYS: Decryption key will be deleted permanently and recovery will be impossible All your Data will be Published and/or Sold to any third-parties Information regarding vulnerabilities of your network also can be published and/or shared IF WE MAKE A DEAL: We will provide you with the Decryption Key and Manual how-to-use We will remove all your files from our file-storage with proof of Deletion We guarantee to avoid sharing any details with third-parties We will provide you the penetration report and list of security-recommendations Instructions for contacting our team Download & Install TOR browser: https://torproject.org For contact us via LIVE CHAT open our > Website: xjakumydulag5z65c7kd4agbxfyajpbrj6wfanj3koyhb5asq2x4e7yd.onion > Login: [snip] > Password: [snip] If Tor is restricted in your area, use VPN All your Data will be published in 3 Days if NO contact made Your Decryption keys will be permanently destroyed in 3 Days if no contact made Your Data will be published if you will hire third-party negotiators to contact us
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (0)
Search, filter and paginate the victim timeline for Chilelocker.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|