AgeLocker
Malware⚠️ Overview
AgeLocker is a ransomware strain first detected in July 2021, attributed by researchers at CrowdStrike to the eCrime threat group UNC2447. It is categorized as a human-operated ransomware that leverages initial access via exploitation of vulnerable edge devices, particularly SonicWall SMA 100 series appliances (CVE-2021-20016), and later moved to deploying backdoors like Cobalt Strike and Metasploit for lateral movement.
🔧 Technical Capabilities
AgeLocker uses a multi-stage infection chain starting with exploitation of CVE-2021-20016 (a pre-authentication SQL injection vulnerability in SonicWall SMA 100 series) to deploy a reconnaissance script, then drops Cobalt Strike beacons for persistence and command-and-control (C2) communication over HTTPS. The ransomware payload itself, written in C++, performs partial file encryption using a combination of AES-256 and RSA-2048, targeting specific file extensions (e.g., .doc, .xls, .pdf, .jpg, .sql) and appending the .agelocker extension. It deletes Volume Shadow Copies via `vssadmin.exe` and disables Windows Defender through registry modifications. Evasion techniques include using process hollowing to inject into legitimate processes (e.g., `svchost.exe`) and encoding its configuration in a hardcoded JSON string.
📜 History & Notable Incidents
AgeLocker first appeared in July 2021, with initial incidents targeting healthcare, manufacturing, and professional services in North America and Europe. In August 2021, Cybereason reported a campaign exploiting the aforementioned SonicWall vulnerability, with the attackers using compromised VPN accounts to move laterally. A notable incident involved a U.S. healthcare organization where the ransomware was delivered after initial access via a SonicWall SMA appliance. No CVEs beyond CVE-2021-20016 are directly linked, and no law enforcement actions have been publicly documented as of early 2024.
🔍 Detection Indicators
Known file hashes for AgeLocker samples include SHA256 `3a7c45e1f9b2d8c0...` (as published by CrowdStrike). Behavioral indicators include the execution of `vssadmin delete shadows /all /quiet`, creation of files named `RECOVER-FILES.txt` in every encrypted directory, and network traffic to C2 IPs associated with known bulletproof hosting providers. Registry keys modified include `HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesSystemEnableLUA` set to 0. The ransomware uses a hardcoded User-Agent string `Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36` during beaconing.
☠️ Risk & Impact
AgeLocker causes irreversible file encryption, leading to operational downtime and data loss if backups are inaccessible. The financial impact includes ransom demands ranging from $50,000 to $500,000, with payments typically made in Monero or Bitcoin. Affected sectors include healthcare, manufacturing, and legal services, with data exfiltration prior to encryption used as leverage for double-extortion.
🛡️ Mitigation
Mitigation includes patching SonicWall SMA 100 series against CVE-2021-20016, enforcing multi-factor authentication on VPNs, and deploying endpoint detection and response (EDR) rules to block Cobalt Strike beacons and process hollowing. Regularly tested offline backups and monitoring for `vssadmin` deletion commands are critical countermeasures.
Similar Threats
Free Threat Visibility
Get Visibility Into Automated Threats Reaching Your Server
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.