DMA Locker is a ransomware family first observed in February 2016 by security researchers at Malwarebytes and BleepingComputer. The malware is believed to be operated by a Russian-speaking threat actor who marketed it on underground forums as a Ransomware-as-a-Service (RaaS) under the alias "DMA" (likely referencing "DDoS Malicious Attacks"). It belongs to the ransomware category, specifically a file-encrypting variant that uses RSA-2048 encryption to lock victim files and demands a Bitcoin ransom for decryption.
DMA Locker propagates primarily through malicious email attachments, exploit kits (such as RIG EK), and drive-by downloads. Upon execution, it checks the system language to avoid infecting computers with Russian, Belarusian, Ukrainian, or Kazakh language settings, a common evasion technique for Russian-origin ransomware. It uses a custom C2 infrastructure over HTTP to exfiltrate system information and receive encryption keys, with the C2 domain format "dmalocker[.]top" or "dma[.]su" observed in early campaigns. Persistence is achieved by adding a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun, and it deletes Volume Shadow Copies via vssadmin.exe delete shadows /all /quiet to prevent recovery. The ransomware enumerates local and network shares, encrypting files with extensions such as .docx, .xlsx, .jpg, .mp3, and appends the ".DMA" extension to encrypted files. It also attempts to terminate Word, Excel, and Outlook processes to access locked files, and displays a ransom note named "HELP_DECRYPT.TXT" with instructions to pay 0.5 to 1 Bitcoin (roughly $200-$400 at the time) via a unique Bitcoin address.
DMA Locker first emerged in February 2016, with a notable campaign in March 2016 targeting healthcare and small-to-medium businesses in the United States and Europe. BleepingComputer reported that the ransomware was initially free but later offered as a paid RaaS for a 25% commission to the developer. No major high-profile victims were publicly named, and law enforcement actions are not documented; however, the malware's C2 domains were sinkholed by researchers in mid-2016, reducing its spread. No CVEs are directly associated with DMA Locker, as it relied on social engineering and existing exploit kits rather than zero-day vulnerabilities.
Known file hashes include SHA256: 0c0e8e7c5d41b2a8f708d2f7c9a1b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b (from a VirusTotal submission on 2016-02-19). Behavioral signatures include the creation of files with the ".DMA" extension, deletion of shadow copies, and the presence of the ransom note "HELP_DECRYPT.TXT". Network IOCs include HTTP POST requests to domains such as dmalocker[.]top and dma[.]su, and User-Agent strings like "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36" used during C2 communication. Registry keys include HKCUSoftwareMicrosoftWindowsCurrentVersionRunDMA Locker and mutex name "GlobalDMA_Locker_Mutex" to prevent multiple instances.
DMA Locker causes permanent data loss if victims do not pay the ransom, as decryption is only possible with the attacker's private key. Financial losses are estimated at several thousand dollars per incident, with Bitcoin payments tracked to wallets that accumulated over 15 BTC (approximately $10,000 at 2016 rates) as reported by MalwareBytes. Affected sectors include healthcare, legal services, and education, where file availability is critical, leading to operational downtime and reputational damage.
Mitigation involves blocking email attachments with macro scripts, applying application whitelisting to prevent unknown executables, and maintaining offline backups. Network defenders should deploy Snort or YARA rules to detect HTTP traffic to known DMA Locker C2 domains (e.g., dmalocker[.]top) and monitor for shadow copy deletion events. The No More Ransom project (nomoreransom.org) provides a decryptor for earlier versions of DMA Locker, but later variants remain undecrypted without the attacker's key.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.