WastedLocker — Malware Profile
WastedLocker is a ransomware family attributed to Indrik Spider that has been used since at least May 2020. WastedLocker has been used against a broad variety of sectors, including manufacturing, information technology, and media.
MITRE ATT&CK techniques (20)
- T1012 Query Registry
- T1027.013 Encrypted/Encoded File
- T1027.016 Junk Code Insertion
- T1059.003 Windows Command Shell
- T1083 File and Directory Discovery
- T1106 Native API
- T1112 Modify Registry
- T1120 Peripheral Device Discovery
- T1135 Network Share Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1222.001 Windows Permissions
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1497.001 System Checks
- T1543.003 Windows Service
- T1548.002 Bypass User Account Control
- T1564.001 Hidden Files and Directories
- T1564.004 NTFS File Attributes
- T1569.002 Service Execution
- T1574.001 DLL