logo

Cryptolocker variant Torrentlocker making new victims in NL

ID: 15d3d14a-0295-5fcd-b9d8-560448347ecd

STIX ID: report--15d3d14a-0295-5fcd-b9d8-560448347ecd

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2014-11-06

Date Updated: 2026-04-27

Author: Fox It

...
...

This Fox-IT report documents a Torrentlocker ransomware spam campaign in the Netherlands (November 2014) that used malicious Word macros to download a dropper which installs ransomware that encrypts user files; it provides detection and containment guidance, host- and network-based IOCs (email subjects and sender, dropper URL, file paths, C2 hostname and IP addresses), and advice on isolation, backup restoration, and risks of paying the ransom.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.