Ransomware Group intelligence
Lockergoga
InactiveTrack Lockergoga with 4 published victims in a single intelligence view.
Overview
Lockergoga is tracked by Breach House as a ransomware group with 4 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (4)
Typical Attacks (7)
▼How Lockergoga typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via LockerGoga.
-
T1070.004 File Deletion Stealth
What they do: LockerGoga has been observed deleting its original launcher after execution.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1553.002 Code Signing Defense Impairment
What they do: LockerGoga has been signed with stolen certificates in order to make it look more legitimate.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1570 Lateral Tool Transfer Lateral Movement
What they do: LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating.
What that means: Adversaries may transfer tools or other files between systems in a compromised environment.
-
T1486 Data Encrypted for Impact Impact
What they do: LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1529 System Shutdown/Reboot Impact
What they do: LockerGoga has been observed shutting down infected systems.
What that means: Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
-
T1531 Account Access Removal Impact
What they do: LockerGoga has been observed changing account passwords and logging off current users.
What that means: Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
Victims (4)
Search, filter and paginate the victim timeline for Lockergoga. Showing 1–4 of 4.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Hexion Inc. and MPM Holdings Inc. id265 View details | United States | Services | — | |
|
No additional victim description available. |
|||||
| Ransomware | Norsk Hydro id262 View details | Norway | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Momentive (industrial firm) id261 View details | United States | Manufacturing / Engineering | — | |
|
No additional victim description available. |
|||||
| Ransomware | Altran Technologies id258 View details | France | IT | — | |
|
No additional victim description available. |
|||||