astralocker
- First seen
- 2021-01-01 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:56:48
Context
AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-extortion, smash-and-grab approach: distributed directly via phishing Microsoft Word documents containing embedded OLE objects. Once executed, it kills security and backup processes, deletes shadow copies, and encrypts files using modified HC-128 and Curve25519 algorithms, appending extensions like .Astra or .babyk. A “smash-and-grab” style attack, it’s less methodical than more sophisticated campaigns—deploying ransomware immediately upon user action rather than conducting prolonged network reconnaissance. In mid-2022, the operator ceased ransomware operations, releasing decryptors and announcing a pivot to cryptojacking.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Astralocker_Auto (yara-rule)
Reports & references
- ransomlook.io — Astralocker (report)
- reversinglabs.com — Smash And Grab Astralocker 2 Pushes Ransomware Direct From Office Docs (report)
- emsisoft.com — Astralocker (report)
- infosecinstitute.com — Astralocker Releases The Ransomware Decryptors (report)
- heimdalsecurity.com — Astralocker Ransomware Goes Offline And Makes Decryptors Available (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Astralocker (report)
- emsisoft.com — Astralocker (report)
- blog.reversinglabs.com — Smash And Grab Astralocker 2 Pushes Ransomware Direct From Office Docs (report)
- bleepingcomputer.com — Astralocker Ransomware Shuts Down And Releases Decryptors (report)
- blog.malwarebytes.com — Astralocker 2 0 Ransomware Isnt Going To Give You Your Files Back (report)