RegretLocker
- First seen
- 2023-09-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:27:28
Targeted industries: technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical financial-services
Context
RegretLocker is a new ransomware that has been found in the wild in the last month that does not only encrypt normal files on disk like other ransomwares. When running, it will particularly search for VHD files, mount them using Windows Virtual Storage API, and then encrypt all the files it finds inside of those VHD files.
Detection coverage
- 2 YARA rules
Detection rules
- ARKBIRD_SOLG_Ran_Regretlocker_Oct_2020_1 (yara-rule)
- MALPEDIA_Win_Regretlocker_Auto (yara-rule)
Reports & references
- chuongdong.com — Regretlocker (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Regretlocker (report)
- twitter.com — 1321375502179905536 (report)
- bleepingcomputer.com — New Regretlocker Ransomware Targets Windows Virtual Machines (report)