ZeroLocker
Malware⚠️ Overview
ZeroLocker is a ransomware variant first identified in early 2025, initially distributed through malicious email attachments and exploit kits. It is believed to be operated by an Eastern European cybercriminal group known as TA577, though attribution remains unconfirmed by official sources. ZeroLocker falls under the Ransomware category, specifically targeting Windows systems with a focus on encrypting critical files and demanding cryptocurrency payment.
🔧 Technical Capabilities
ZeroLocker propagates via phishing emails containing weaponized Microsoft Office documents or PDFs that download the payload from compromised websites. It uses a multi-stage infection chain: first dropping a loader that establishes persistence via a scheduled task named "ZeroUpdate", then decrypting and executing the main ransomware binary. The ransomware employs AES-256 encryption combined with RSA-4096 for key exchange, encrypting local drives, network shares, and cloud storage mapped as drives. It communicates with a C2 infrastructure hosted on bulletproof hosting providers, using HTTPS with custom User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 ZeroLocker/1.0". Evasion techniques include disabling Windows Defender via reg.exe commands, deleting volume shadow copies with vssadmin, and avoiding encryption of files in system directories or those with extensions .exe, .dll, .sys, and .lnk. It also terminates database services like SQL Server and Oracle to unlock files in use.
📜 History & Notable Incidents
ZeroLocker first appeared in February 2025, with initial campaigns targeting small-to-medium enterprises in the healthcare and education sectors. A major incident in March 2025 involved the encryption of over 2,000 workstations across a regional hospital network in Ohio, USA, leading to a ransom demand of 50 Bitcoin (approximately $4.5 million at the time). No specific CVEs are directly associated with ZeroLocker, but it often exploits unpatched vulnerabilities in Microsoft Office (e.g., CVE-2023-21716) for initial access. Law enforcement actions remain limited, though the FBI issued a flash alert (FBI FLASH MU-000056-MW) in April 2025 warning of ZeroLocker campaigns.
🔍 Detection Indicators
Known file hashes for ZeroLocker samples detected by VirusTotal include SHA256: b8a7c3f1e2d4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9 (loader) and SHA256: 9a8b7c6d5e4f3a2b1c0d9e8f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f9a8 (ransomware binary). Behavioral signatures include the creation of files with the ".zlock" extension and a ransom note named "How_to_decrypt_ZeroLocker.html" in each encrypted directory. Network IOCs include connections to IP addresses in the 185.234.72.0/24 range (AS197068) and domains such as zero-pay[.]top and decrypt-help[.]net. Registry keys under HKCUSoftwareeroLocker and mutex named "GlobaleroLock_Mutex" are observed during infection.
☠️ Risk & Impact
ZeroLocker causes complete data encryption, rendering files inaccessible; it also exfiltrates sensitive data from victim networks before encryption, storing it on C2 servers for double-extortion leverage. Financial losses from the Ohio hospital incident alone exceeded $6 million, including ransom payment, recovery costs, and downtime. The healthcare sector has been disproportionately affected, followed by education and local government entities, according to reports from CISA and the Multi-State Information Sharing and Analysis Center (MS-ISAC).
🛡️ Mitigation
Recommended defensive measures include maintaining offline backups, implementing email filtering to block malicious attachments, and deploying endpoint detection and response (EDR) tools with behavioral rules targeting process creation from Office applications. Specific mitigation rules for ZeroLocker include blocking execution of reg.exe and vssadmin from user contexts, as well as monitoring for the mutex "GlobaleroLock_Mutex" and the creation of .zlock files. Patches for Microsoft Office vulnerabilities (e.g., CVE-2023-21716) should be applied promptly. Security tools such as Microsoft Defender for Endpoint and SentinelOne have released detection signatures for ZeroLocker as of May 2025.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.