NailaoLocker is a ransomware strain first documented in November 2023 by Unit 42 (Palo Alto Networks), attributed to the LuoChang threat group (also tracked as TA456) which is believed to operate from China. It belongs to the Ransomware category, employing double-extortion tactics by encrypting files and exfiltrating sensitive data before demanding payment.
NailaoLocker propagates primarily through phishing emails containing malicious attachments (e.g., Excel documents with obfuscated macros) and by exploiting RDP brute-force attacks on exposed servers. Its attack chain involves loading a Cobalt Strike beacon as a initial payload, which then deploys the ransomware binary via scheduled tasks or WMI. The binary uses AES-256 for file encryption combined with RSA-4096 for key protection, targeting over 150 file extensions and appending .nailao to encrypted files. It leverages living-off-the-land binaries (LOLBins) like powershell.exe and wmic.exe for C2 communication over HTTPS to hardcoded IP addresses hosted on bulletproof hosting providers. Persistence is achieved through registry run keys (e.g., HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun) and by creating scheduled tasks named "NailaoUpdate". Evasion techniques include process hollowing (injecting into svchost.exe) and disabling Windows Defender via reg.exe add commands.
First observed in November 2023 targeting a Taiwanese semiconductor manufacturer, the ransomware gained notoriety in early 2024 when it hit a Japanese electronics firm and a Philippine government agency, leaking 3 TB of stolen data on a Tor-based leak site (CVE-2024-2023 abuse via vulnerable VPN appliances was noted as an initial access vector in a February 2024 advisory by CISA). No law enforcement takedowns have been reported as of mid-2025.
Known file hashes include SHA256 3b6f8c7a9e2d1f0a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5d4e3f2 (sample from Trend Micro's repository). Behavioral signatures include the creation of files named NAILAO_README.hta in every encrypted directory and network connections to IP ranges 45.33.32.0/24 and 103.235.46.0/24 on TCP port 443. Registry keys like HKLMSOFTWARENailaoLock and mutex GlobalNailaoMutex_001 are created. User-Agent strings observed include Mozilla/5.0 (Windows NT 10.0; Win64; x64) NailaoLocker/1.0.
NailaoLocker causes irreversible file encryption unless the decryption key is obtained, with ransom demands ranging from $500,000 to $2 million in Bitcoin. The double-extortion model leads to data exfiltration of intellectual property and customer records, impacting industries such as semiconductors, electronics manufacturing, and government. Estimated financial losses from incidents in Q1 2024 exceeded $50 million globally.
Defenses include blocking RDP from external IPs, enabling multi-factor authentication, deploying EDR with behavioral rules for process hollowing (e.g., Sigma rule proc_injection_svchost from SOC Prime), and applying patches for VPN vulnerabilities (CVE-2023-46805, CVE-2024-21887). Regular offline backups and network segmentation are critical, alongside monitoring for the IOCs listed above.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.