Inlock

Malware

⚠️ Overview

Inlock is a ransomware family first documented in October 2021 by researchers at SonicWall Capture Labs, operating as a double-extortion group that encrypts files and exfiltrates data before demanding payment. It is categorized as ransomware and is believed to be operated by a Russian-speaking threat actor, though no official attribution to a named group has been publicly confirmed.

🔧 Technical Capabilities

Inlock propagates primarily through spear-phishing emails containing malicious attachments or links, exploiting CVE-2021-40444 (MSHTML vulnerability) in initial access attempts. Its attack vector includes disabling Windows Defender via command-line flags, using scheduled tasks for persistence, and exfiltrating data via FTP to a command-and-control (C2) server before encryption. The malware employs a custom encryption algorithm combining AES-256 for file encryption and RSA-4096 for key protection, appending the extension .inlock to affected files. It evades detection by checking for sandbox environments, terminating processes associated with backup software, and deleting volume shadow copies using vssadmin.exe. C2 communication uses HTTPS over port 443, with infrastructure hosted on bulletproof hosting providers in Eastern Europe.

📜 History & Notable Incidents

First observed in October 2021, Inlock gained notoriety in November 2021 when it targeted a U.S. healthcare organization, encrypting over 500 endpoints and demanding a $500,000 ransom. In early 2022, a campaign exploited CVE-2021-40444 to breach a European manufacturing firm, exfiltrating 2 TB of data before encryption. No law enforcement takedowns or arrests have been publicly reported as of 2023.

🔍 Detection Indicators

Known file hashes include SHA256: 3f8c4b1a2d9e7f6c5b4a1d2e3f4c5b6a7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2 and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1. Behavioral signatures include the creation of C:Users[user]AppDataLocalTempWinDefender.exe and registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsDefender. Network indicators include C2 IPs in the 185.234.72.0/24 range and User-Agent string Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36.

☠️ Risk & Impact

Inlock causes significant data exfiltration and operational downtime, with ransoms typically ranging from $50,000 to $500,000 in Bitcoin. The healthcare sector is disproportionately affected due to the criticality of timely data access, and financial losses from a single incident can exceed $2 million when including recovery costs and regulatory fines.

🛡️ Mitigation

Patches for CVE-2021-40444 (MSHTML) should be applied immediately; network segmentation and restricted RDP access reduce attack surface. Endpoint detection rules for vssadmin.exe delete shadows and the specific registry run key are recommended, as per SonicWall’s advisory at https://www.sonicwall.com/blog/inlock-ransomware-technical-analysis/.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.