ColdLock

First seen
2020-05-01 00:00:00
Malware type
ransomware
Family
Malware family
Profile updated
2026-07-07 14:53:17

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:tw country_code:hk

Context

ColdLock is a ransomware family known for targeting financial services and governmental organizations primarily in Taiwan and Hong Kong. It encrypts files and demands a ransom for decryption, causing significant operational disruption.

Reports & references

  • medium.com — China Linked Threat Group Targets Taiwan Critical Infrastructure Smokescreen Ransomware C2A155Aa53D5 (report)
  • Trend Micro — U S Justice Department Charges Apt41 Hackers Over Global Cyberattacks (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Coldlock (report)

External references