LockerGoga
MITRE ATT&CK: S0372 View on attack.mitre.org
Aliases: LockerGoga
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2025-10-08 17:16:23
- Profile updated
- 2026-07-07 12:40:47
Targeted industries: manufacturing energy-and-utilities
Targeted regions: country_code:no country_code:fr country_code:uk
Context
LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including industrial and manufacturing firms.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to LockerGoga (S0372). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | LockerGoga.exe | 2025-10-08 | 2 |
Detection coverage
- 1 YARA rules
- 200 Sigma rules
Malware & tools used
- File Deletion (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- System Shutdown/Reboot (attack-pattern)
- Account Access Removal (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Code Signing (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Loss of Productivity and Revenue (attack-pattern)
- Ethernet (attack-pattern)
- Loss of View (attack-pattern)
- Wi-Fi (attack-pattern)
- Loss of Control (attack-pattern)
Used by threat actors
- FIN6 (threat-actor)
Detection rules
- MALPEDIA_Win_Lockergoga_Auto (yara-rule)
Related threat objects
- Nodera Ransomware (malware)
- MegaCortex (malware)
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- Mandiant — Pick Six Intercepting A Fin6 Intrusion (report)
- pwc.co.uk — Cyber Threats 2019 Retrospect (report)
- Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
- cert.ssi.gouv.fr — Certfr 2019 Act 005 (report)
- bleepingcomputer.com — New Lockergoga Ransomware Allegedly Used In Altran Attack (report)
- ransomlook.io — Lockergoga (report)
- cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
- Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
- Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
- McAfee — Csi Evidence Indicators For Targeted Ransomware Attacks Part Ii (report)
- europol.europa.eu — 12 Targeted For Involvement In Ransomware Attacks Against Critical Infrastructure (report)
- npu.gov.ua — Kiberpolicziya Vikrila Transnaczionalne Zlochinne Ugrupovannya U Nanesenni Inozemnim Kompaniyam 120 Miljoniv Dolariv Zbitkiv (report)
- Mandiant — Rpt M Trends 2020 (report)
- govcert.admin.ch — Severe Ransomware Attacks Against Swiss Smes (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lockergoga (report)
- dragos.com — Spyware Stealer Locker Wiper Lockergoga Revisited (report)
- Cisco Talos — Lockergoga (report)
- abuse.io — Lockergoga.Txt (report)
- youtube.com — Watch (report)
- nrk.no — Skreddersydd Dobbeltangrep Mot Hydro 1.14480202 (report)
- cert.ssi.gouv.fr — Certfr 2019 Cti 001 (report)
- helpnetsecurity.com — Aurora Decrypter Mira Decrypter (report)
- bleepingcomputer.com — Fbi Issues Alert For Lockergoga And Megacortex Ransomware (report)
- doublepulsar.com — How Lockergoga Took Down Hydro Ransomware Used In Targeted Attacks Aimed At Big Business C666551F5880 (report)