logo

WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group

ID: a1d22c43-a672-58cf-87bf-d5a5356f8b6e

STIX ID: report--a1d22c43-a672-58cf-87bf-d5a5356f8b6e

Feed Name: Fox-IT blog

Threat Score
78/100

Date Published: 2020-06-23

Date Updated: 2026-04-27

...
...

This technical report by Fox-IT/NCC Group analyzes WastedLocker, a targeted ransomware variant linked to Evil Corp active since May 2020, detailing attribution, distribution via the SocGholish fake-update framework, custom CobaltStrike loaders and the CryptOne crypter, UAC bypass and privilege escalation techniques, file-encryption and exclusion behaviors, and providing extensive IoCs (domains, sample hashes, beacon configs) and a decrypter reference to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.