HexaLocker
- First seen
- 2024-08-09 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-06-04 15:58:54
- Profile updated
- 2026-07-07 15:05:18
Targeted industries: financial-services healthcare-and-pharmaceutical technology-and-telecommunications
Context
On August 9th, 2024, the HexaLocker team advertised a new Windows ransomware on its Telegram channel. The message included a demonstration video and text promoting a Golang ransomware that implements a proprietary algorithm.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Hexalocker (report)
- synacktiv.com — Lapsus Is Dead Long Live Hexalocker (report)
- cyble.com — Hexalocker V2 Being Proliferated By Skuld Stealer (report)