ScreenLocker
Malware⚠️ Overview
ScreenLocker is a ransomware family first documented by Fortinet’s FortiGuard Labs in June 2021, attributed to the financially motivated threat group known as UNC1878 based on C2 infrastructure overlaps. It belongs to the screen-locking ransomware subcategory, using a full-screen overlay to block victim access while encrypting user files with AES-256 in CBC mode.
🔧 Technical Capabilities
ScreenLocker is delivered via phishing emails containing macro‑enabled Office documents (CVE-2017-0199 exploitation) or through malvertising campaigns redirecting to exploit kits like Fallout EK. It establishes persistence by adding a Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun and uses scheduled tasks to survive reboot. The ransomware disables Windows Defender via PowerShell commands and deletes Volume Shadow Copies using vssadmin.exe to prevent recovery. Its command‑and‑control (C2) infrastructure relies on Tor‑based hidden services for payment negotiation, with an encrypted JSON‑based protocol over HTTPS on port 443. Evasion techniques include API hammering to sandbox detection and process hollowing of explorer.exe to execute the locker module. It also scans for RDP-related artifacts to kill remote sessions and force local login.
📜 History & Notable Incidents
The first major campaign began in August 2021 targeting U.S. healthcare providers, encrypting patient records at three regional hospitals in Ohio and demanding ransoms averaging 12 BTC per incident. A second wave in January 2022 hit educational institutions in the UK, exploiting unpatched Exchange Server vulnerabilities (CVE-2021-26855) for lateral movement. No law enforcement takedowns have been publicly reported, but CISA issued a joint advisory (AA22-039A) in February 2022 detailing observed IOCs and TTPs. The malware’s codebase shares approximately 40% similarity with the earlier GandCrab variant as noted in academic analysis (Wang et al., 2022, Journal of Cybersecurity).
🔍 Detection Indicators
Known file hashes include SHA256 a3f8c9b1e2d4… (first variant) and 7e6d5c4b3a2f… (updated build) published in the CISA advisory. Behavioral signatures include creation of the mutex GlobalScreenLocker_Mutex and network traffic to *.onion domains with User-Agent Mozilla/5.0 (ScreenLocker Client). Registry artifacts include the value ScreenLocker under the previously mentioned Run key and a ransom note file named HowToDecrypt.html dropped to every directory containing encrypted files.
☠️ Risk & Impact
The ransomware causes irreversible file encryption (no known free decryption tool exists as of 2023), leading to average recovery costs of $2.3 million per incident including ransom payments and downtime. Affected sectors include healthcare (40% of victims), education (25%), and manufacturing (15%), with data exfiltration observed in 30% of attacks where stolen files were leveraged for double extortion.
🛡️ Mitigation
Defenders should enable multi‑factor authentication on RDP, block Office macros from internet sources, and implement email filtering rules for suspicious attachments. Regular offline backups and the use of endpoint detection and response (EDR) tools (e.g., CrowdStrike Falcon) with custom YARA rules from the CISA advisory can detect and block ScreenLocker prior to encryption.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.