Ransomware Group intelligence
Wastedlocker
InactiveTrack Wastedlocker with 2 published victims in a single intelligence view.
Overview
Wastedlocker is tracked by Breach House as a ransomware group with 2 published victims.
United States is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Leak Status Distribution
- Leaked 0 0.0%
- Pending 2 100.0%
- Deleted 0 0.0%
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (2)
Typical Attacks (20)
▼How Wastedlocker typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via WastedLocker.
-
T1059.003 Windows Command Shell Execution
What they do: WastedLocker has used cmd to execute commands on the system.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
T1569.002 Service Execution Execution
What they do: WastedLocker can execute itself as a service.
What that means: Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
-
What they do: WastedLocker has performed DLL hijacking before execution.
What that means: Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses.
-
What they do: WastedLocker can modify registry values within the Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry key.
What that means: Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
-
What they do: WastedLocker created and established a service that runs until the encryption process is complete.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
T1548.002 Bypass User Account Control Privilege Escalation
What they do: WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later.
What that means: Adversaries may bypass UAC mechanisms to elevate process privileges on system.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: The WastedLocker payload includes encrypted strings stored within the .bss section of the binary file.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1027.016 Junk Code Insertion Stealth
What they do: WastedLocker contains junk code to increase its entropy and hide the actual code.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: WastedLocker's custom cryptor, CryptOne, used an XOR based algorithm to decrypt the payload.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
What they do: WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique.
What that means: Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
-
T1564.001 Hidden Files and Directories Stealth
What they do: WastedLocker has copied a random file from the Windows System32 folder to the %APPDATA% location under a different hidden filename.
What that means: Adversaries may set files and directories to be hidden to evade detection mechanisms.
-
T1564.004 NTFS File Attributes Stealth
What they do: WastedLocker has the ability to save and execute files as an alternate data stream (ADS).
What that means: Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
-
T1222.001 Windows Permissions Defense Impairment
What they do: WastedLocker has a command to take ownership of a file and reset the ACL permissions using the takeown.exe /F filepath command.
What that means: Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
-
T1012 Query Registry Discovery
What they do: WastedLocker checks for specific registry keys related to the UCOMIEnumConnections and IActiveScriptParseProcedure32 interfaces.
What that means: Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
-
T1083 File and Directory Discovery Discovery
What they do: WastedLocker can enumerate files and directories just prior to encryption.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1120 Peripheral Device Discovery Discovery
What they do: WastedLocker can enumerate removable drives prior to the encryption process.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1135 Network Share Discovery Discovery
What they do: WastedLocker can identify network adjacent and accessible drives.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: WastedLocker can encrypt data and leave a ransom note.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: WastedLocker can delete shadow volumes.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
wastedlocker.txt
[snip] YOUR NETWORK IS ENCRYPTED NOW USE [email protected] | [email protected] TO GET THE PRICE FOR YOUR DATA DO NOT GIVE THIS EMAIL TO 3RD PARTIES DO NOT RENAME OR MOVE THE FILE THE FILE IS ENCRYPTED WITH THE FOLLOWING KEY: [begin_key]*[end_key] KEEP IT
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (2)
Search, filter and paginate the victim timeline for Wastedlocker. Showing 1–2 of 2.
| Type | Target | Discovered | Country | Business Category | Intel Link | Leak status |
|---|---|---|---|---|---|---|
| Ransomware | Boyne Resorts id498 View details | United States | Hospitality / Food & Beverage / Tourism | — | pending | |
|
No additional victim description available. |
||||||
| Ransomware | Garmin id444 View details | United States | Other | — | pending | |
|
No additional victim description available. |
||||||