logo

LockCrypt Ransomware

ID: ecafeba2-16c9-57e8-989d-0e864b4fa932

STIX ID: report--ecafeba2-16c9-57e8-989d-0e864b4fa932

Feed Name: Binary Defense Blog

Threat Score
75/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

Attackers have been conducting RDP brute-force attacks since June to deploy a ransomware variant called "LockCrypt" that encrypts files (appending ".lock"), deletes backups, persists on infected servers, and exfiltrates base64-encoded machine data to a server in Iran; victims in the US, UK, South Africa, India, and the Philippines were asked to pay 0.5–1 BTC per server, with reported payments, and recommended mitigations include enforcing strong passwords, enabling two-factor authentication, and restricting RDP exposure to the internet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.