LockFile
- First seen
- 2021-07-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-06-10 08:51:33
- Profile updated
- 2026-07-07 13:02:30
Targeted industries: education-and-nonprofits healthcare-and-pharmaceutical financial-services
Targeted regions: country_code:us country_code:gb country_code:fr
Context
LockFile is a ransomware that emerged in July 2021, known for encrypting files and demanding ransom payments. It targets various industries, including healthcare and financial services, primarily in the US, UK, and France.
Detection coverage
- 4 YARA rules
Detection rules
- ARKBIRD_SOLG_MAL_Loader_Lockfile_Aug_2021_1 (yara-rule)
- DITEKSHEN_MALWARE_Win_Lockfile (yara-rule)
- DITEKSHEN_MALWARE_Win_Surtr (yara-rule)
- MALPEDIA_Win_Lockfile_Auto (yara-rule)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- secureworks.com — Bronze Starlight Ransomware Operations Use Hui Loader (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- bleepingcomputer.com — Microsoft Exchange Servers Hacked To Deploy Hive Ransomware (report)
- decoded.avast.io — Decryptor For Atomsilo And Lockfile Ransomware (report)
- nsfocusglobal.com — Insights Into Ransomware Spread Using Exchange 1 Day Vulnerabilities 1 2 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lockfile (report)
- blog.cyble.com — Lockfile Ransomware Using Proxyshell Attack To Deploy Ransomware (report)
- thehackernews.com — Lockfile Ransomware Bypasses Protection (report)
- news.sophos.com — Lockfile Ransomwares Box Of Tricks Intermittent Encryption And Evasion (report)
- Broadcom/Symantec — Lockfile Ransomware New Petitpotam Windows (report)
- csoonline.com — Lockfile Ransomware Uses Intermittent Encryption To Evade Detection (report)
- news.sophos.com — Proxyshell Vulnerabilities In Microsoft Exchange What To Do (report)
- twitter.com — 1428750497872232459 (report)