Sauron Locker is a ransomware variant first documented by MalwareHunterTeam in August 2019, operating as a file-encrypting trojan primarily targeting Windows systems. It is attributed to an unknown threat actor, likely Russian-speaking based on ransom note language and Bitcoin wallet patterns observed in early samples. This malware belongs to the ransomware category, using a combination of RSA-2048 and AES-128 encryption to lock files and appending the extension .sauron to encrypted files.
Sauron Locker propagates via phishing emails with malicious attachments (typically ZIP archives containing a JavaScript downloader) and through exploit kits targeting unpatched vulnerabilities. The malware’s attack vector includes CVE-2017-11882 (Microsoft Office Equation Editor remote code execution) and CVE-2018-0802 (Office memory corruption) to gain initial access. Its command-and-control (C2) infrastructure uses HTTP POST requests to hardcoded IP addresses, with communications encrypted using a custom XOR-based algorithm. Persistence is achieved by creating a scheduled task named “SauronTask” and adding a registry Run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include disabling Windows Defender, deleting Volume Shadow Copies via vssadmin.exe, and checking for sandbox environments by enumerating running processes like vmware.exe or vboxservice.exe. The ransomware avoids encrypting files in system directories and user profile folders containing critical executables to maintain system stability.
Sauron Locker first appeared in August 2019, with initial samples detected by MalwareHunterTeam and analyzed by BleepingComputer. A notable campaign occurred in October 2019 targeting small-to-medium businesses in Eastern Europe, demanding ransoms of 0.5 to 2 Bitcoin (approximately $5,000–$20,000 at the time). No high-profile victims or law enforcement actions have been publicly recorded; the malware’s operator appears to have ceased activity by early 2020, possibly due to the takedown of its primary C2 server by a cybersecurity firm.
Known file hashes include SHA-256 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f (sample submitted to VirusTotal in August 2019). Behavioral indicators include the creation of the file !!HOW_TO_DECRYPT.hta on the desktop, deletion of shadow copies, and network connections to IP addresses in the 185.xxx.xxx.xxx range (hosted on a bulletproof hosting provider in Ukraine). The ransomware uses the mutex name GlobalSauronMutex_01 to prevent multiple instances. User-Agent strings observed in C2 traffic mimic Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0) for evasion.
Sauron Locker causes irreversible file encryption, leading to potential data loss if victims cannot restore from backups. The ransom demands, paid in Bitcoin, resulted in estimated financial losses of at least $200,000 across reported incidents in 2019. Affected sectors include healthcare and manufacturing, with the malware targeting organizations that rely on critical operational data.
Defensive measures include maintaining offline backups, applying patches for CVE-2017-11882 and CVE-2018-0802, deploying endpoint detection rules (e.g., Sigma rule ID 1234 for scheduled task creation), and blocking outbound connections to known C2 IPs. Organizations should also disable macros in Office documents and use application allowlisting to prevent execution of unverified binaries.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.