logo

Ransomware Tracker (Entry #258): NailaoLocker

ID: 4c4cbe36-91a3-50a2-9875-e03e4cac3910

STIX ID: report--4c4cbe36-91a3-50a2-9875-e03e4cac3910

Feed Name: WatchGuard Secplicity Blog

Threat Score
85/100

Date Published: 2025-06-19

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

WatchGuard summarizes research revealing the Green Nailao campaign (June–October 2024) that exploited a critical Check Point zero-day (CVE-2024-24919) to infiltrate networks—primarily European healthcare—using PlugX and ShadowPad for persistence and exfiltration, and deploying NailaoLocker ransomware (AES-256-CTR, ".locked") with ransom contact via ProtonMail; research attributes activity to Chinese-based actors and reports victims across Europe, Asia, and South America.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.