Mount Locker

Malware

⚠️ Overview

Mount Locker is a ransomware family first identified in July 2020 by security researchers at Palo Alto Networks, categorized as a human-operated ransomware variant that employs double extortion tactics through data exfiltration and file encryption. The threat actors behind Mount Locker — tracked as TA551 or Shathak, an initial access broker — have been linked to the deployment of Mount Locker alongside other ransomware like Conti and Quantum, though the group's exact affiliation remains debated among analysts.

🔧 Technical Capabilities

Mount Locker uses the ChaCha20 stream cipher combined with RSA-2048 asymmetric encryption to encrypt files, appending a random extension such as .locker or .mountlocker to affected files (MITRE ATT&CK T1486). It gains initial access through phishing emails delivering malicious attachments or exploiting vulnerabilities in RDP and VPN appliances (T1190). The ransomware terminates over 50 Windows services including database and backup services using the net stop command and deletes Volume Shadow Copies via vssadmin.exe to prevent recovery (T1490). Persistence is achieved through registry run keys (T1547.001), and it communicates with its command-and-control infrastructure over HTTPS using hardcoded IP addresses or domain-generation algorithms (T1071.001). Evasion techniques include disabling Windows Defender real-time monitoring through PowerShell commands and checking for analysis tools like process explorers to avoid sandbox detection (T1562.001, T1497).

📜 History & Notable Incidents

Mount Locker first surfaced in July 2020, with early victims reported in the healthcare and education sectors; a notable incident involved the attack on the University of California in 2020. In March 2021, the group claimed responsibility for breaching East Bay Municipal Utility District in California, leaking stolen data on their leak site. Law enforcement actions have not publicly led to arrests, though the group's infrastructure has been disrupted through takedowns of hosting providers.

🔍 Detection Indicators

Known SHA256 hashes for Mount Locker samples have been documented on VirusTotal and AlienVault OTX. Behavioral signatures include the execution of vssadmin delete shadows /all /quiet, net stop commands targeting SQL and backup services, and the creation of ransom notes named !!!_READ_ME_!!! or Mount Locker.txt. Network Indicators of Compromise (IOCs) include connections to IP addresses in the 185.141.25.0/24 range and User-Agent strings such as “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36”.

☠️ Risk & Impact

Mount Locker causes significant operational disruption by encrypting critical files and servers, with ransom demands typically ranging from $100,000 to several million dollars in Bitcoin. The double extortion model, where stolen data is published on a leak site if ransoms are unpaid, has led to data breaches affecting hospitals, utilities, and municipal governments across North America and Europe.

🛡️ Mitigation

Defenders should enforce multi-factor authentication on RDP and VPN services, maintain offline backups, and deploy endpoint detection and response (EDR) solutions configured with YARA rules for Mount Locker indicators. Regular patching of vulnerabilities in Citrix, Fortinet, and Microsoft Exchange servers (CVE-2021-26855, CVE-2020-1472) reduces initial access vectors exploited by the group.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.