astralocker

First seen
2021-01-01 00:00:00
Malware type
ransomware
Profile updated
2026-07-07 13:56:48

Context

AstraLocker first appeared in 2021, likely as a fork of Babuk ransomware using leaked source code. It follows a single-extortion, smash-and-grab approach: distributed directly via phishing Microsoft Word documents containing embedded OLE objects. Once executed, it kills security and backup processes, deletes shadow copies, and encrypts files using modified HC-128 and Curve25519 algorithms, appending extensions like .Astra or .babyk. A “smash-and-grab” style attack, it’s less methodical than more sophisticated campaigns—deploying ransomware immediately upon user action rather than conducting prolonged network reconnaissance. In mid-2022, the operator ceased ransomware operations, releasing decryptors and announcing a pivot to cryptojacking.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Astralocker_Auto (yara-rule)

Reports & references

  • ransomlook.io — Astralocker (report)
  • reversinglabs.com — Smash And Grab Astralocker 2 Pushes Ransomware Direct From Office Docs (report)
  • emsisoft.com — Astralocker (report)
  • infosecinstitute.com — Astralocker Releases The Ransomware Decryptors (report)
  • heimdalsecurity.com — Astralocker Ransomware Goes Offline And Makes Decryptors Available (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Astralocker (report)
  • emsisoft.com — Astralocker (report)
  • blog.reversinglabs.com — Smash And Grab Astralocker 2 Pushes Ransomware Direct From Office Docs (report)
  • bleepingcomputer.com — Astralocker Ransomware Shuts Down And Releases Decryptors (report)
  • blog.malwarebytes.com — Astralocker 2 0 Ransomware Isnt Going To Give You Your Files Back (report)

External references