WastedLocker

MITRE ATT&CK: S0612 View on attack.mitre.org

Aliases: WastedLocker

First seen
2020-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Operating systems
windows
Related IoCs
6 (6 malicious)
Last IoC activity
2026-09-01 03:03:23
Profile updated
2026-07-07 12:39:03

Targeted industries: manufacturing technology-and-telecommunications media-and-entertainment

Context

WastedLocker is a ransomware family attributed to Indrik Spider that has been used since at least May 2020. WastedLocker has been used against a broad variety of sectors, including manufacturing, information technology, and media.

Recent IoC activity

6 malicious indicators in Maltiverse are attributed to WastedLocker (S0612). The 6 most recently updated:

Detection coverage

  • 2 YARA rules
  • 448 Sigma rules

Malware & tools used

  • Windows Service (attack-pattern)
  • Hidden Files and Directories (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • System Checks (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Query Registry (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Native API (attack-pattern)
  • DLL (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Service Execution (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Windows Permissions (attack-pattern)

Used by threat actors

Detection rules

  • TRELLIX_ARC_RANSOM_Wastedlocker (yara-rule)
  • MALPEDIA_Win_Wastedlocker_Auto (yara-rule)

Reports & references

  • pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
  • CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
  • CrowdStrike — Report2021Gtr (report)
  • bbc.com — World Us Canada 53195749 (report)
  • secureworks.com — Gold Drake (report)
  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • proofpoint.com — First Step Initial Access Leads Ransomware (report)
  • CrowdStrike — Hades Ransomware Successor To Indrik Spiders Wastedlocker (report)
  • Cisco Talos — Ctir Trends Winter 2020 21 (report)
  • news.sophos.com — The Ransomware Threat Intelligence Center (report)
  • Broadcom/Symantec — The Ransomware Threat September 2021 (report)
  • paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
  • pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
  • Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
  • killingthebear.jorgetesta.tech — Evil Corp (report)
  • Mandiant — Unc2165 Shifts To Evade Sanctions (report)
  • assets.sentinelone.com — Sentinellabs Evilcorp (report)
  • bleepingcomputer.com — New Evil Corp Ransomware Mimics Payloadbin Gang To Evade Us Sanctions (report)
  • sentinelone.com — S1 Sentinellabs Sanctionsbedamned Final 02 (report)
  • blogs.cisco.com — Wastedlocker Goes Big Game Hunting In 2020 (report)
  • blog.malwarebytes.com — Threat Spotlight Wastedlocker Customized Ransomware (report)
  • research.nccgroup.com — Wastedlocker A New Ransomware Variant Developed By The Evil Corp Group (report)
  • blog.truesec.com — Are The Notorious Cyber Criminals Evil Corp Actually Russian Spies (report)
  • bleepingcomputer.com — Evil Corp Switches To Hades Ransomware To Evade Sanctions (report)
  • medium.com — The Road To Ransomware Resilience C1Ca37036Efd (report)

External references