MountLocker ransomware now working through criminal affiliates

Ransomware-as-a-service could become a major threat, warns BlackBerry researchers

Visual representation of ransomware by showing encrypted files on a display

Security researchers have warned of a new strain of ransomware that uses affiliates to spread the malware

In a blog post, researchers at BlackBerry said that MountLocker has been available as ransomware as a service since July and was updated in November to broaden the file types it targeted and evade security software.

The malware itself, at less than 100Kb in size, is lightweight and simple in construction. It is typically deployed as either an x86 or x64 Windows portable executable (PE) file, although occasionally as a Microsoft Installer (MSI) package.

The ransomware encrypts data of victims and demands Bitcoin as ransom. The hackers also threaten to leak stolen information if money is not received.

BlackBerry researchers said that the ransomware uses an affiliate scheme to find victims. Its investigations found that threat actors often used remote desktop (RDP) with compromised credentials to gain access to a victim’s environment. In one instance, after establishing a foothold in an organisation, there was a delay of several days before activity resumed.

“It is likely that the threat actors were negotiating with the MountLocker operators to join their affiliate program and obtain the ransomware during this pause. Upon obtaining the MountLocker ransomware, the threat actors were observed returning with several “public” tools, including CobaltStrike Beacon and AdFind from Joeware,” researchers said.

Blackberry noted that only five victims are listed on MountLocker's "News & Leaks" site hosted on the darknet, but are likely to increase.

Researchers said that the operators behind MountLocker are “clearly just warming up”.

"After a slow start in July, they are rapidly gaining ground, as the high-profile nature of extortion and data leaks drive ransom demands ever higher. MountLocker affiliates are typically fast operators, rapidly exfiltrating sensitive documents and encrypting them across key targets in a matter of hours,” they said.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

Best ransomware removal tools
ransomware

Best ransomware removal tools

22 Jan 2021
Russian spy agencies warn of US cyber retaliation
hacking

Russian spy agencies warn of US cyber retaliation

25 Jan 2021
Global ransom DDoS extortionists are retargeting companies
distributed denial of service (DDOS)

Global ransom DDoS extortionists are retargeting companies

22 Jan 2021
Pixlr data breach exposes over 1.9 million user records
data breaches

Pixlr data breach exposes over 1.9 million user records

22 Jan 2021

Most Popular

How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

21 Jan 2021
WhatsApp could face €50 million GDPR fine
General Data Protection Regulation (GDPR)

WhatsApp could face €50 million GDPR fine

25 Jan 2021
Trump pardons convicted ex-Google engineer Levandowski
intellectual property

Trump pardons convicted ex-Google engineer Levandowski

20 Jan 2021