FortiGuard Labs is aware of a report that LokiLocker ransomware is equipped with built-in wiper functionality. The ransomware targets the Windows OS and is capable of erasing all non-system files and overwriting the Master Boot Record (MBR) if the victim opts not to pay the ransom, leaving the compromised machine unusable. According to the report, most victims of LokiLocker ransomware are in Eastern Europe and Asia.Why is this Significant?This is significant because LokiLocker ransomware has built-in wiper functionality which can overwrite the MBR and delete all non-system files on the compromised machine if the victim does not pay ransom in a set time frame. Successfully overwriting the MBR will leave the machine unusable.What is LokiLocker Ransomware?LokiLocker is a .NET ransomware that has been active since as early as August 2021. The ransomware encrypts files on the compromised machines and demands ransom from the victim to recover the encrypted files. The ransomware adds a “.Loki” file extension to the files it encrypted. It also leaves a ransom note in a Restore-My-Files.txt file. The malware is protected with NETGuard, an open-source tool for protecting .NET applications, as well as KoiVM, a virtualizing protector for .NET applications.LokiLocker has a built-in configuration file, which contains information such as the attacker’s email address, campaign or affiliate name, Command-and-Control (C2) server address and wiper timeout. Wiper timeout is set to 30 days by default. The value tells the ransomware to wait 30 days before deleting non-system files and overwriting the Master Boot Record (MBR) of the compromised machine. The configuration also has execution options which controls what actions the ransomware should or should not carry out on the compromised machine. The execution options include not wiping the system and the MBR, not encrypting the C Drive and not scanning for and encrypting network shares. The wiping option is set to false by default, however the option can be modified by the attacker.How is LokiLocker Ransomware Distributed?While the current infection vector is unknown, early LokiLocker variants were distributed through Trojanized brute-checker hacking tools. According to the public report, most victims of LokiLocker ransomware are in Eastern Europe and Asia. Fortinet’s telemetry indicates the C2 domain was accessed the most from India, followed by Canada, Chile and Turkey.What is the Status of Coverage?FortiGuard Labs provide the following AV coverage:W32/DelShad.GRG!tr.ransomW32/DelShad.GSE!tr.ransomW32/DelShad.GUJ!tr.ransomW32/Filecoder.AKJ!trW32/Generic.AC.171!trW32/PossibleThreatW32/Ramnit.AMSIL/Filecoder.AKJ!trMSIL/Filecoder.AKJ!tr.ransomMSIL/Filecoder_LokiLocker.D!trMSIL/Filecoder.4AF0!tr.ransomMSIL/Filecoder.64CF!tr.ransomPossibleThreatAll known network IOC’s are blocked by the FortiGuard WebFiltering client.
More Stories
cpp-httplib-0.19.0-1.fc42
FEDORA-2025-c0ec6fa21b Packages in this update: cpp-httplib-0.19.0-1.fc42 Update description: Automatic update for cpp-httplib-0.19.0-1.fc42. Changelog * Mon Feb 17 2025 Orion Poplawski...
cpp-httplib-0.19.0-1.fc43
FEDORA-2025-53d4bfcda2 Packages in this update: cpp-httplib-0.19.0-1.fc43 Update description: Automatic update for cpp-httplib-0.19.0-1.fc43. Changelog * Mon Feb 17 2025 Orion Poplawski...
gnutls-3.8.9-4.fc43 nettle-3.10.1-1.fc43
FEDORA-2025-246cd08b09 Packages in this update: gnutls-3.8.9-4.fc43 nettle-3.10.1-1.fc43 Update description: Update gnutls and nettle to the latest upstream release. The gnutls...
USN-7269-1: Intel Microcode vulnerabilities
Ke Sun, Paul Grosen and Alyssa Milburn discovered that some Intel® Processors did not properly implement Finite State Machines (FSMs)...
Monero 18.3.4 zero-day DoS vulnerability has been dropped publicly on social network.
Posted by upper.underflow via Fulldisclosure on Feb 16 Hello, About an hour ago, a group appearing to be named WyRCV2...
Netgear Router Administrative Web Interface Lacks Transport Encryption By Default
Posted by Ryan Delaney via Fulldisclosure on Feb 16 <!-- # Exploit Title: Netgear Router Administrative Web Interface Lacks Transport...