Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors adminlocker

Description

AdminLocker is a relatively low-profile ransomware strain first observed around December 2021, encrypting victim files and demanding Bitcoin ransom via a Tor-based portal, operated by a lone actor or small closed group with no evidence of an affiliate model.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

AdminLocker is a medium-sophistication ransomware strain first observed in early 2022, targeting organizations for financial gain through encryption and Tor-based portals.

Goals & Targeting

AdminLocker's primary goal is financial gain through ransomware activities. While specific targeted sectors and countries are not well-documented, the strain likely targets generic or mid-sized business segments where ransoms can be effectively extracted without significant attention from law enforcement or media. The group appears to focus on organizational impact rather than high-profile attacks.

Enhanced Description

AdminLocker is a relatively low-profile ransomware strain that emerged around December 2021. It encrypts victim files and demands Bitcoin as ransom through a Tor-based portal, suggesting an operational model likely maintained by a lone actor or small, closed group with no evidence of an affiliate program. The strain demonstrates moderate technical capabilities, focusing on financial gain rather than high-profile targets. Despite being less prominent, AdminLocker poses a threat to businesses and organizations due to its effective encryption methods and persistence in targeting victims for ransom.

Key Capabilities

  • Ransomware encryption
  • Tor-based C2 communication
  • Email phishing campaigns

MITRE ATT&CK Tactics

Defense Evasion
Exfiltration

ATT&CK Techniques

T1055
T1078
T1496.001

Software / Tooling

AdminLocker Ransomware

Campaigns & Victims

Known campaigns are limited due to low profile, but AdminLocker has shown persistence in targeting diverse regions and industries seeking quick financial recovery. victims typically include businesses, healthcare institutions, and educational organizations. Notable for its methodical encryption process and reliance on Tor.

IOC Patterns

  • Ransomware-related file encryption patterns
  • Tor-based command and control infrastructure

Recommended Actions

  • Enhance network monitoring for suspicious encryption activities.
  • Regularly back up critical data to mitigate ransom demands.
  • Educate users on phishing emails with malicious attachments.

Suggested Tags

Ransomware
Financial-Motivation
Generic-Sectors

Confidence Assessment

Moderate confidence due to limited available data. Gaps exist in exact targeting patterns and detailed TTP analysis beyond encryption methods.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Motivation
Generic-Sectors

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.