logo

Files Locked Behind a White Padlock: A Warning from WhiteLock Ransomware

ID: 77340523-5ce4-518e-aecb-f30f5f9eb1d2

STIX ID: report--77340523-5ce4-518e-aecb-f30f5f9eb1d2

Feed Name: ASEC

Threat Score
70/100

Date Published: 2026-07-07

Date Updated: 2026-07-20

Author: ATCP

...
...

WhiteLock is a ransomware strain that encrypts Windows user files using AES-CBC and protects the AES key with RSA-2048 retrieved from an external server, appending a .Fbin extension to encrypted files and dropping a c0ntact.Txt ransom note; it also terminates remote access services (AnyDesk, TeamViewer), changes the desktop wallpaper to pressure victims, and is observed to follow initial access and information-stealing activity. The report details infection routines (MAC hashed to identify victims), exclusion lists, IOCs (file extension, ransom note name, wallpaper change), and recommended defenses including EDR, backups, monitoring of remote access tools, and network egress controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.