Skip to main content

Boteraser | Website and Server Security Solutions

NailaoLocker

Malware

⚠️ Overview

NailaoLocker is a ransomware strain first documented in November 2023 by Unit 42 (Palo Alto Networks), attributed to the LuoChang threat group (also tracked as TA456) which is believed to operate from China. It belongs to the Ransomware category, employing double-extortion tactics by encrypting files and exfiltrating sensitive data before demanding payment.

🔧 Technical Capabilities

NailaoLocker propagates primarily through phishing emails containing malicious attachments (e.g., Excel documents with obfuscated macros) and by exploiting RDP brute-force attacks on exposed servers. Its attack chain involves loading a Cobalt Strike beacon as a initial payload, which then deploys the ransomware binary via scheduled tasks or WMI. The binary uses AES-256 for file encryption combined with RSA-4096 for key protection, targeting over 150 file extensions and appending .nailao to encrypted files. It leverages living-off-the-land binaries (LOLBins) like powershell.exe and wmic.exe for C2 communication over HTTPS to hardcoded IP addresses hosted on bulletproof hosting providers. Persistence is achieved through registry run keys (e.g., HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun) and by creating scheduled tasks named "NailaoUpdate". Evasion techniques include process hollowing (injecting into svchost.exe) and disabling Windows Defender via reg.exe add commands.

📜 History & Notable Incidents

First observed in November 2023 targeting a Taiwanese semiconductor manufacturer, the ransomware gained notoriety in early 2024 when it hit a Japanese electronics firm and a Philippine government agency, leaking 3 TB of stolen data on a Tor-based leak site (CVE-2024-2023 abuse via vulnerable VPN appliances was noted as an initial access vector in a February 2024 advisory by CISA). No law enforcement takedowns have been reported as of mid-2025.

🔍 Detection Indicators

Known file hashes include SHA256 3b6f8c7a9e2d1f0a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2 (sample from Trend Micro's repository). Behavioral signatures include the creation of files named NAILAO_README.hta in every encrypted directory and network connections to IP ranges 45.33.32.0/24 and 103.235.46.0/24 on TCP port 443. Registry keys like HKLMSOFTWARENailaoLock and mutex GlobalNailaoMutex_001 are created. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) NailaoLocker/1.0.

☠️ Risk & Impact

NailaoLocker causes irreversible file encryption unless the decryption key is obtained, with ransom demands ranging from $500,000 to $2 million in Bitcoin. The double-extortion model leads to data exfiltration of intellectual property and customer records, impacting industries such as semiconductors, electronics manufacturing, and government. Estimated financial losses from incidents in Q1 2024 exceeded $50 million globally.

🛡️ Mitigation

Defenses include blocking RDP from external IPs, enabling multi-factor authentication, deploying EDR with behavioral rules for process hollowing (e.g., Sigma rule proc_injection_svchost from SOC Prime), and applying patches for VPN vulnerabilities (CVE-2023-46805, CVE-2024-21887). Regular offline backups and network segmentation are critical, alongside monitoring for the IOCs listed above.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.