Ransomware Group intelligence
Wastedlocker
InactiveTrack Wastedlocker with 2 published victims in a single intelligence view.
Overview
Wastedlocker is tracked by Breach House as a ransomware group with 2 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (2)
Typical Attacks (20)
▼How Wastedlocker typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via WastedLocker.
-
T1059.003 Windows Command Shell Execution
What they do: WastedLocker has used cmd to execute commands on the system.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1569.002 Service Execution Execution
What they do: WastedLocker can execute itself as a service.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: WastedLocker has performed DLL hijacking before execution.
What that means: Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses.
-
What they do: WastedLocker can modify registry values within the Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry key.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: WastedLocker created and established a service that runs until the encryption process is complete.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: The WastedLocker payload includes encrypted strings stored within the .bss section of the binary file.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1027.016 Junk Code Insertion Stealth
What they do: WastedLocker contains junk code to increase its entropy and hide the actual code.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: WastedLocker's custom cryptor, CryptOne, used an XOR based algorithm to decrypt the payload.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
What they do: WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique.
What that means: Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
-
T1564.001 Hidden Files and Directories Stealth
What they do: WastedLocker has copied a random file from the Windows System32 folder to the %APPDATA% location under a different hidden filename.
What that means: Adversaries may set files and directories to be hidden to evade detection mechanisms.
-
T1564.004 NTFS File Attributes Stealth
What they do: WastedLocker has the ability to save and execute files as an alternate data stream (ADS).
What that means: Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
-
T1222.001 Windows Permissions Defense Impairment
What they do: WastedLocker has a command to take ownership of a file and reset the ACL permissions using the takeown.exe /F filepath command.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1012 Query Registry Discovery
What they do: WastedLocker checks for specific registry keys related to the UCOMIEnumConnections and IActiveScriptParseProcedure32 interfaces.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1083 File and Directory Discovery Discovery
What they do: WastedLocker can enumerate files and directories just prior to encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1120 Peripheral Device Discovery Discovery
What they do: WastedLocker can enumerate removable drives prior to the encryption process.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: WastedLocker can identify network adjacent and accessible drives.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: WastedLocker can encrypt data and leave a ransom note.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: WastedLocker can delete shadow volumes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
wastedlocker.txt
[snip] YOUR NETWORK IS ENCRYPTED NOW USE [email protected] | [email protected] TO GET THE PRICE FOR YOUR DATA DO NOT GIVE THIS EMAIL TO 3RD PARTIES DO NOT RENAME OR MOVE THE FILE THE FILE IS ENCRYPTED WITH THE FOLLOWING KEY: [begin_key]*[end_key] KEEP IT
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (2)
Search, filter and paginate the victim timeline for Wastedlocker. Showing 1–2 of 2.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Boyne Resorts id498 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
No additional victim description available. |
|||||
| Ransomware | Garmin id444 View details | United States | Other | — | |
|
No additional victim description available. |
|||||