Skip to content

Ransomware

Mount Locker

aka DagonLocker · MountLocker · QuantumLocker

According to BlackBerry, MountLocker is a Ransomware-as-a-Service (RaaS), active since July 2020 The MountLocker ransomware was updated during early November 2020 to broaden the targeting of file type

Mount Locker, also known as DagonLocker, MountLocker, QuantumLocker, is a Windows ransomware operated by Vanilla Tempest.

Background

BlackBerry describes MountLocker as a Ransomware-as-a-Service (RaaS) offering that has been operating since July 2020. An update in early November 2020 widened the range of file types it targets and improved its evasion of security tools. It encrypts victim files with ChaCha20 and protects those file keys using RSA-2048. While the scheme has no obvious flaws permitting straightforward key recovery, the way MountLocker generates its keys is cryptographically weak and could potentially be attacked.


Source: Malpedia (Fraunhofer FKIE).