Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware LockerGoga

LockerGoga

TLP:CLEAR
Family

AI Analysis

· 2 days ago

Executive Summary

LockerGoga is a ransomware targeting industrial and manufacturing firms in Europe since early 2019. It encrypts files with AES‑128, removes recovery options, and includes a backdoor for exfiltration and lateral movement. Timely detection requires monitoring specific file names, encryption activity, and anomalous remote access attempts.

Enhanced Description

LockerGoga is a sophisticated ransomware family that emerged in early 2019 and has predominantly targeted European industrial, manufacturing, and critical infrastructure organizations. The malware encrypts victim files using AES‑128 encryption and then protects the master key with a public RSA key held by the attackers. In addition to file encryption, LockerGoga deletes System Restore points (via VSS shadow copies) and disables Windows Defender services to hinder forensic recovery. Known variants also include a remote backdoor component that can receive commands over HTTPS or via a custom TCP channel, enabling attackers to exfiltrate data or conduct additional post‑infection reconnaissance. During the infection lifecycle, LockerGoga initially compromises a system through phishing emails containing malicious attachments or by exploiting exposed Remote Desktop Protocol (RDP) services with stolen credentials. Once privileges are elevated, it enumerates file names, compresses encrypted payloads for exfiltration, and propagates laterally using valid accounts discovered during credential dumping. The ransom note requests payment via cryptocurrency and threatens long‑term data exposure if the attackers’ demands are not met. Operational security reports from Unit42 and Carbon Black highlight frequent victimization of European industrial enterprises, underscoring LockerGoga’s focus on high‑impact sectors where downtime translates directly into significant financial loss. The threat actor behind LockerGoga exhibits advanced persistence capabilities, careful evasion tactics (e.g., avoiding known detection signatures), and a flexible approach to payload delivery, making it a persistent risk for organizations lacking rigorous endpoint protection and network segmentation.

Key Capabilities

  • Encrypts victim files using AES-128
  • Deletes System Restore points to prevent rollback
  • Implements a HTTPS/TCP-based backdoor for command execution
  • Exfiltrates encrypted payloads
  • Easily propagates via compromised RDP or stolen credentials

ATT&CK Techniques

T1486
T1105
T1070.004

Recommended Actions

  • Deploy EDR solutions that detect rapid file‑encryption patterns and deletion of shadow copies
  • Block inbound/outbound traffic on non‑essential ports used by LockerGoga’s backdoor (e.g., custom HTTPS/TCP)
  • Enforce MFA and least‑privilege policies for RDP access
  • Maintain offline, immutable backups of critical industrial data
  • Use host-based integrity monitoring to alert on suspicious binaries like LockerGoga.exe

Suggested Tags

ransomware
locker-goga
industrial-attack
critical-infrastructure
phishing
remote-desktop-protocol

Confidence Assessment

The available information comes from reputable security research outlets such as Unit42 and Carbon Black, providing strong confidence in basic operational details. However, gaps remain regarding the full spectrum of infection vectors, precise key‑management implementation, and potential exfiltration methods used by certain variants.

Description

LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including industrial and manufacturing firms.(Citation: Unit42 LockerGoga 2019)(Citation: CarbonBlack LockerGoga 2019)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.