AdminLocker is a relatively low-profile ransomware strain first observed around December 2021, encrypting victim files and demanding Bitcoin ransom via a Tor-based portal, operated by a lone actor or small closed group with no evidence of an affiliate model.
Objectives
Executive Summary
AdminLocker is a medium-sophistication ransomware strain first observed in early 2022, targeting organizations for financial gain through encryption and Tor-based portals.
Goals & Targeting
AdminLocker's primary goal is financial gain through ransomware activities. While specific targeted sectors and countries are not well-documented, the strain likely targets generic or mid-sized business segments where ransoms can be effectively extracted without significant attention from law enforcement or media. The group appears to focus on organizational impact rather than high-profile attacks.
Enhanced Description
AdminLocker is a relatively low-profile ransomware strain that emerged around December 2021. It encrypts victim files and demands Bitcoin as ransom through a Tor-based portal, suggesting an operational model likely maintained by a lone actor or small, closed group with no evidence of an affiliate program. The strain demonstrates moderate technical capabilities, focusing on financial gain rather than high-profile targets. Despite being less prominent, AdminLocker poses a threat to businesses and organizations due to its effective encryption methods and persistence in targeting victims for ransom.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Known campaigns are limited due to low profile, but AdminLocker has shown persistence in targeting diverse regions and industries seeking quick financial recovery. victims typically include businesses, healthcare institutions, and educational organizations. Notable for its methodical encryption process and reliance on Tor.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence due to limited available data. Gaps exist in exact targeting patterns and detailed TTP analysis beyond encryption methods.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics