Executive Summary
LockerGoga is a ransomware targeting industrial and manufacturing firms in Europe since early 2019. It encrypts files with AES‑128, removes recovery options, and includes a backdoor for exfiltration and lateral movement. Timely detection requires monitoring specific file names, encryption activity, and anomalous remote access attempts.
Enhanced Description
LockerGoga is a sophisticated ransomware family that emerged in early 2019 and has predominantly targeted European industrial, manufacturing, and critical infrastructure organizations. The malware encrypts victim files using AES‑128 encryption and then protects the master key with a public RSA key held by the attackers. In addition to file encryption, LockerGoga deletes System Restore points (via VSS shadow copies) and disables Windows Defender services to hinder forensic recovery. Known variants also include a remote backdoor component that can receive commands over HTTPS or via a custom TCP channel, enabling attackers to exfiltrate data or conduct additional post‑infection reconnaissance. During the infection lifecycle, LockerGoga initially compromises a system through phishing emails containing malicious attachments or by exploiting exposed Remote Desktop Protocol (RDP) services with stolen credentials. Once privileges are elevated, it enumerates file names, compresses encrypted payloads for exfiltration, and propagates laterally using valid accounts discovered during credential dumping. The ransom note requests payment via cryptocurrency and threatens long‑term data exposure if the attackers’ demands are not met. Operational security reports from Unit42 and Carbon Black highlight frequent victimization of European industrial enterprises, underscoring LockerGoga’s focus on high‑impact sectors where downtime translates directly into significant financial loss. The threat actor behind LockerGoga exhibits advanced persistence capabilities, careful evasion tactics (e.g., avoiding known detection signatures), and a flexible approach to payload delivery, making it a persistent risk for organizations lacking rigorous endpoint protection and network segmentation.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information comes from reputable security research outlets such as Unit42 and Carbon Black, providing strong confidence in basic operational details. However, gaps remain regarding the full spectrum of infection vectors, precise key‑management implementation, and potential exfiltration methods used by certain variants.
LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including industrial and manufacturing firms.(Citation: Unit42 LockerGoga 2019)(Citation: CarbonBlack LockerGoga 2019)