WastedLocker
MITRE ATT&CK: S0612 View on attack.mitre.org
Aliases: WastedLocker
- First seen
- 2020-05-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 6 (6 malicious)
- Last IoC activity
- 2026-09-01 03:03:23
- Profile updated
- 2026-07-07 12:39:03
Targeted industries: manufacturing technology-and-telecommunications media-and-entertainment
Context
WastedLocker is a ransomware family attributed to Indrik Spider that has been used since at least May 2020. WastedLocker has been used against a broad variety of sectors, including manufacturing, information technology, and media.
Recent IoC activity
6 malicious indicators in Maltiverse are attributed to WastedLocker (S0612). The 6 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 2026-08-30_39886e46851c9960061bfca04fdba2d1_elex_wastedlocker | 2026-09-01 | 1 |
| file sample | 2026-08-20_4b6b01621f8ad69459c77f17237ee6d7_elex_wastedlocker | 2026-08-21 | 1 |
| file sample | 3ced78b45d457c3b10ec16519f9e4b8a246d6d090c91e2d4065659ef95af641f | 2026-08-12 | 1 |
| file sample | b79fd82092d65067433e404796552d8bb4abcc645b44f9714336c58127841aa5 | 2026-08-12 | 1 |
| file sample | 0b944a210fa1ef6f90d206bb0ccacf26eaf83baa8413c8aec0347fa4fb7974c7 | 2026-08-12 | 1 |
| file sample | f695017c1b191d81d2716dfca14b63bc3a0142e28cd49b7eb12d83341dca2576 | 2026-08-12 | 1 |
Detection coverage
- 2 YARA rules
- 448 Sigma rules
Malware & tools used
- Windows Service (attack-pattern)
- Hidden Files and Directories (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Modify Registry (attack-pattern)
- System Checks (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Windows Command Shell (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Query Registry (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Native API (attack-pattern)
- DLL (attack-pattern)
- File and Directory Discovery (attack-pattern)
- NTFS File Attributes (attack-pattern)
- Network Share Discovery (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Service Execution (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Windows Permissions (attack-pattern)
Used by threat actors
- TA575 (threat-actor)
- Indrik Spider (threat-actor)
Detection rules
- TRELLIX_ARC_RANSOM_Wastedlocker (yara-rule)
- MALPEDIA_Win_Wastedlocker_Auto (yara-rule)
Reports & references
- pwc.co.uk — Pwc Cyber Threats 2020 A Year In Retrospect (report)
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- CrowdStrike — Report2021Gtr (report)
- bbc.com — World Us Canada 53195749 (report)
- secureworks.com — Gold Drake (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- proofpoint.com — First Step Initial Access Leads Ransomware (report)
- CrowdStrike — Hades Ransomware Successor To Indrik Spiders Wastedlocker (report)
- Cisco Talos — Ctir Trends Winter 2020 21 (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- paloaltonetworks.com — Unit42 Ransomware Threat Report 2021 (report)
- pwc.co.uk — What Is Behind Ransomware Attacks Increase (report)
- Broadcom/Symantec — Sed Fy22Q2 Ses Ransomware Threat Landscape Wp (report)
- killingthebear.jorgetesta.tech — Evil Corp (report)
- Mandiant — Unc2165 Shifts To Evade Sanctions (report)
- assets.sentinelone.com — Sentinellabs Evilcorp (report)
- bleepingcomputer.com — New Evil Corp Ransomware Mimics Payloadbin Gang To Evade Us Sanctions (report)
- sentinelone.com — S1 Sentinellabs Sanctionsbedamned Final 02 (report)
- blogs.cisco.com — Wastedlocker Goes Big Game Hunting In 2020 (report)
- blog.malwarebytes.com — Threat Spotlight Wastedlocker Customized Ransomware (report)
- research.nccgroup.com — Wastedlocker A New Ransomware Variant Developed By The Evil Corp Group (report)
- blog.truesec.com — Are The Notorious Cyber Criminals Evil Corp Actually Russian Spies (report)
- bleepingcomputer.com — Evil Corp Switches To Hades Ransomware To Evade Sanctions (report)
- medium.com — The Road To Ransomware Resilience C1Ca37036Efd (report)
External references
- mitre-attack — S0612
- WastedLocker
- NCC Group WastedLocker June 2020
- Symantec WastedLocker June 2020
- Sentinel Labs WastedLocker July 2020
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy