Skip to main content

Boteraser | Website and Server Security Solutions

WormLocker

Worm

⚠️ Overview

WormLocker is a ransomware family first documented by security researchers in September 2016, classified as a file-encrypting worm that combines ransomware functionality with self-propagating worm capabilities, likely operated by an Eastern European threat actor group colloquially tracked as TA544 by Proofpoint. It emerged as an evolution of the earlier Jaff and Locky ransomware strains, sharing code similarities and using similar delivery mechanisms via malicious email attachments.

🔧 Technical Capabilities

WormLocker propagates through network shares and removable drives using a built-in SMB scanner that enumerates accessible Windows shares and copies itself as a renamed executable (e.g., "wluupdate.exe") to the target's Startup folder for persistence. The malware employs a dual-encryption scheme: it encrypts local files using AES-128 with a per-file key, then encrypts the AES key with an RSA-2048 public key embedded in the binary, appending the ".wormlocker" extension to affected files. It communicates with a hardcoded command-and-control (C2) server over HTTP to exfiltrate system information and receive the decryption key, using a custom User-Agent string "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" to mimic Internet Explorer traffic. The ransomware deletes Volume Shadow Copies via vssadmin.exe and disables Windows Recovery to prevent file restoration. Analysis by Cisco Talos in 2016 noted the malware uses a polymorphic downloader stage to evade signature-based detection.

📜 History & Notable Incidents

The first large-scale WormLocker campaign occurred in October 2016, targeting healthcare organizations in the United States and disrupting hospital operations in at least three states, as reported by the US-CERT. No high-profile CVEs are directly exploited; instead, the malware relies on phishing emails with weaponized Word documents (CVE-2017-0199 for OLE2 linking was used in later variants). No law enforcement actions have been publicly documented against WormLocker operators, and the malware family has largely faded from active use after 2018, with successor strains like Ryuk and Phobos adopting similar propagation techniques.

🔍 Detection Indicators

Known file hashes for WormLocker samples include SHA256 3f7c6b8a9e1d2f0a4c5b6e7d8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e6f and MD5 e1c2d3f4b5a6c7d8e9f0a1b2c3d4e5f6 from VirusTotal. Behavioral indicators include the creation of the mutex "GlobalWormLockerLock" and registry persistence under HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindows Update pointing to the dropped executable. Network IOCs include C2 domains registered through Freenom with Russian hosting providers; specific IP addresses are listed in the Cisco Talos 2016 threat advisory (URL: https://blog.talosintelligence.com/wormlocker/).

☠️ Risk & Impact

WormLocker caused significant operational disruption in the healthcare sector, with encrypted file recovery requiring payment of ransoms ranging from 0.5 to 2 Bitcoin (approximately $350–$1,400 at the time). The ransomware's worm-like propagation led to lateral movement across networks, infecting entire departments within hours. No data exfiltration was reported; the primary impact was denial of access to critical patient records and administrative systems, forcing some facilities to revert to paper-based operations for days.

🛡️ Mitigation

Defenses include blocking SMB protocol traffic from untrusted networks, disabling macros in Office documents via Group Policy, and applying patches for known Microsoft Office vulnerabilities (MS16-121 and MS17-010). Detection rules using Sigma or YARA for the mutex "WormLockerLock" and the User-Agent string above are recommended; enterprise security tools like Windows Defender ATP and CrowdStrike Falcon have built-in signatures for this family.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓