HexaLocker

Malware

⚠️ Overview

HexaLocker is a ransomware variant first identified in August 2022 by Cybereason security researchers, primarily targeting small and medium-sized businesses in North America. It is categorized as ransomware and is believed to be operated by a financially motivated Russian-speaking threat group linked to the Phobos ransomware ecosystem due to shared code patterns and C2 infrastructure.

🔧 Technical Capabilities

HexaLocker employs RSA-2048 and AES-256 encryption to lock files, appending the extension .hexalocker to encrypted data. Initial access is gained through RDP brute-force attacks and spear‑phishing emails with malicious macros (MITRE ATT&CK T1566.001, T1078). The ransomware disables Windows Defender and Volume Shadow Copy services using the vssadmin command (T1490). It communicates with a hardcoded C2 server over HTTPS to exfiltrate victim identifiers and receive payment instructions. Persistence is achieved via scheduled tasks (T1053.005) and registry run keys. For evasion, HexaLocker checks for sandbox environments and delays execution if VMware or VirtualBox artifacts are detected.

📜 History & Notable Incidents

The first reported HexaLocker campaign occurred in September 2022, targeting a regional healthcare provider in the United States, leading to a three‑day system outage (Cybereason report, 2022). In November 2022, a variant exploiting the CVE-2021-34527 (PrintNightmare) vulnerability was observed in attacks against manufacturing firms. No law enforcement actions have been documented as of early 2023.

🔍 Detection Indicators

Known file hashes include SHA256:3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4 (from VirusTotal). Behavioral signatures include mass renaming of files to .hexalocker, creation of HEXALOCKER_README.hta in each directory, and outbound connections to IPs in the 185.234.72.0/24 range. Registry keys added include HKCUSoftwareHexaLocker for persistence.

☠️ Risk & Impact

HexaLocker encrypts all user and system files (excluding core OS binaries), rendering them inaccessible without the decryption key. The group demands ransom in Bitcoin ranging from $2,000 to $50,000 per victim, with double‑extortion pressure by threatening to publish exfiltrated data on a leak site. Affected sectors include healthcare, education, and manufacturing, causing operational downtime and data loss.

🛡️ Mitigation

To defend against HexaLocker, organizations should enforce multi‑factor authentication on RDP, apply patches for PrintNightmare (CVE-2021-34527), deploy endpoint detection rules for file-rename events, and maintain offline backups. The MITRE ATT&CK mapping includes T1486 (Data Encrypted for Impact) and T1490 (Inhibit System Recovery).

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.