LockerGoga

MITRE ATT&CK: S0372 View on attack.mitre.org

Aliases: LockerGoga

Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2025-10-08 17:16:23
Profile updated
2026-07-07 12:40:47

Targeted industries: manufacturing energy-and-utilities

Targeted regions: country_code:no country_code:fr country_code:uk

Context

LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including industrial and manufacturing firms.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to LockerGoga (S0372). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample LockerGoga.exe 2025-10-08 2

Detection coverage

  • 1 YARA rules
  • 200 Sigma rules

Malware & tools used

  • File Deletion (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Account Access Removal (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Code Signing (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Loss of Productivity and Revenue (attack-pattern)
  • Ethernet (attack-pattern)
  • Loss of View (attack-pattern)
  • Wi-Fi (attack-pattern)
  • Loss of Control (attack-pattern)

Used by threat actors

  • FIN6 (threat-actor)

Detection rules

  • MALPEDIA_Win_Lockergoga_Auto (yara-rule)

Related threat objects

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • Mandiant — Pick Six Intercepting A Fin6 Intrusion (report)
  • pwc.co.uk — Cyber Threats 2019 Retrospect (report)
  • Microsoft — Human Operated Ransomware Attacks A Preventable Disaster (report)
  • cert.ssi.gouv.fr — Certfr 2019 Act 005 (report)
  • bleepingcomputer.com — New Lockergoga Ransomware Allegedly Used In Altran Attack (report)
  • ransomlook.io — Lockergoga (report)
  • cert.ssi.gouv.fr — Certfr 2020 Cti 001 (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • Mandiant — Financially Motivated Actors Are Expanding Access Into Ot (report)
  • McAfee — Csi Evidence Indicators For Targeted Ransomware Attacks Part Ii (report)
  • europol.europa.eu — 12 Targeted For Involvement In Ransomware Attacks Against Critical Infrastructure (report)
  • npu.gov.ua — Kiberpolicziya Vikrila Transnaczionalne Zlochinne Ugrupovannya U Nanesenni Inozemnim Kompaniyam 120 Miljoniv Dolariv Zbitkiv (report)
  • Mandiant — Rpt M Trends 2020 (report)
  • govcert.admin.ch — Severe Ransomware Attacks Against Swiss Smes (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Lockergoga (report)
  • dragos.com — Spyware Stealer Locker Wiper Lockergoga Revisited (report)
  • Cisco Talos — Lockergoga (report)
  • abuse.io — Lockergoga.Txt (report)
  • youtube.com — Watch (report)
  • nrk.no — Skreddersydd Dobbeltangrep Mot Hydro 1.14480202 (report)
  • cert.ssi.gouv.fr — Certfr 2019 Cti 001 (report)
  • helpnetsecurity.com — Aurora Decrypter Mira Decrypter (report)
  • bleepingcomputer.com — Fbi Issues Alert For Lockergoga And Megacortex Ransomware (report)
  • doublepulsar.com — How Lockergoga Took Down Hydro Ransomware Used In Targeted Attacks Aimed At Big Business C666551F5880 (report)

External references