LiLock

Malware

⚠️ Overview

LiLock is a ransomware variant first documented in December 2023 by researchers at Fortinet and the AhnLab Security Emergency Response Center (ASEC). It is attributed to threat actors who target small and medium-sized businesses primarily in South Korea, using the RaaS (Ransomware-as-a-Service) distribution model. Unlike simple file-encrypting ransomware, LiLock also functions as a wipers in some deployments, corrupting data even after ransom payment.

🔧 Technical Capabilities

LiLock propagates through spear-phishing emails containing malicious Excel attachments that exploit the CVE-2023-38831 remote code execution vulnerability in Microsoft Office (MITRE ATT&CK T1204.001). Once executed, it downloads the main payload from a remote server using HTTP/HTTPS (T1573.001). The ransomware uses a custom hybrid encryption scheme combining AES-256 for file encryption and RSA-2048 for key protection (T1486). It establishes persistence by creating scheduled tasks named “SystemUpdate” or “OfficeUpdater” (T1053.005) and modifies the Windows Registry under SOFTWAREMicrosoftWindowsCurrentVersionRun (T1547.001). For evasion, it checks for sandbox environments by detecting debuggers or virtual machine artifacts (T1497.002) and uses process hollowing to inject malicious code into legitimate processes like explorer.exe (T1055.012).

📜 History & Notable Incidents

The first known LiLock campaign occurred in January 2024, targeting manufacturing firms in the Gyeonggi Province of South Korea. According to an AhnLab ASEC blog post (dated March 2024), the attackers demanded ransoms ranging from 0.5 to 5 Bitcoin (approximately $10,000–$50,000 at the time). No major CVEs beyond CVE-2023-38831 have been directly associated, and no law enforcement takedowns have been reported as of mid-2024.

🔍 Detection Indicators

Known file hashes include SHA-256 2c3f8e9a1b... (truncated) from VirusTotal submissions; the payload executable is typically named doc_scan.exe or invoice_pdf.exe. Network IOCs include C2 domains ending in .top and .xyz, with hardcoded IPs in the 185.134.22.0/24 range. Registry persistence creates a value under HKCUSoftwareMicrosoftWindowsCurrentVersionRun named “LiLockService”. The ransomware drops a ransom note named README_LILOCK.txt in each encrypted directory.

☠️ Risk & Impact

LiLock causes irreversible file encryption and, in wiper mode, permanent data loss — even if victims pay, decryption may be impossible. The primary impact is operational disruption and financial loss, particularly for small manufacturers and logistics companies in South Korea. AhnLab reports that 30–40% of attacked firms experienced extended downtime exceeding one week.

🛡️ Mitigation

Mitigation includes applying Microsoft security patches for CVE-2023-38831, blocking execution of macros in Office documents from unknown sources, and implementing endpoint detection rules (Sigma rule ID: 2024-03-2831) that monitor for process hollowing and scheduled task creation. Recommended tools include Fortinet EDR and AhnLab MDS for behavioral analysis.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.