lokilocker
- Malware type
- ransomware, wiper
- Family
- Malware family
- Last IoC activity
- 2026-07-16 13:00:39
- Profile updated
- 2026-07-07 13:56:07
Targeted industries: government-and-public-sector healthcare-and-pharmaceutical financial-services
Context
Lokilocker is a ransomware family known for encrypting files and, in certain cases, acting as a wiper by irreversibly deleting data from targeted systems. It primarily affects critical sectors such as government, healthcare, and financial services.
Detection coverage
- 3 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Win_Lokilocker (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Ransomware_Lokilocker (yara-rule)
- DITEKSHEN_INDICATOR_KB_ID_Ransomware_Koxic (yara-rule)
Reports & references
- ransomlook.io — Lokilocker (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Lokilocker (report)
- asec.ahnlab.com — 52570 (report)
- theregister.com — Blackberry Lokilocker Ransomware (report)
- msspalert.com — Lokilocker Ransomware May Use False Flag To Avoid Identification (report)
- blogs.blackberry.com — Lokilocker Ransomware (report)