Ransomware Eruption: Novel Locker Malware Flows From ‘Volcano Demon'
ID: bc22514a-4230-50ec-97b0-a34caecc7750
STIX ID: report--bc22514a-4230-50ec-97b0-a34caecc7750
Feed Name: Dark Reading
Date Published: 2024-07-03
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers at Halcyon identified a new ransomware actor called Volcano Demon using a novel locker named LukaLocker (files marked with .nba) that encrypts Windows and Linux systems, exfiltrates data for double extortion, and employs multiple evasive techniques (API obfuscation, clearing logs, killing security/backup services). The actor uses harvested administrative credentials to deploy Linux and Windows components, uses ChaCha8 with ECDH (Curve25519) for encryption, instructs victims to contact via qTox, and has left IoCs (e.g., Protector.exe, Locker.exe, Linux locker/bin, Reboot.bat) uploaded to VirusTotal; defenders are advised to implement MFA and phishing controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
