Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors dagonlocker

Description

Dagon Locker is a ransomware strain that first appeared in early 2023, evolved from the MountLocker/Quantum ransomware lineage, and uses IcedID as an initial access vector before deploying double-extortion attacks with ChaCha20+RSA-2048 encryption. 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Dagon Locker is a medium-sophistication ransomware strain linked to the MountLocker/Quantum lineage, utilizing IcedID for initial access and employing double extortion tactics through ChaCha20+RSA-2048 encryption. Its primary motivation is financial gain, targeting unspecified sectors with a focus on disrupting operations through data encryption. The group operates with moderate technical capabilities but has demonstrated adaptability by leveraging established ransomware infrastructure.

Goals & Targeting

Dagon Locker's strategic objectives revolve around financial gain through ransomware operations. It targets unspecified sectors, but its use of double extortion and encryption suggests a focus on industries with high data sensitivity and recovery costs. The group likely selects victims based on ease of access, system criticality, and potential for significant financial impact. Typical victims may include businesses reliant on IT infrastructure, such as healthcare, manufacturing, or logistics, where operational downtime could lead to substantial economic losses.

Enhanced Description

Dagon Locker represents an evolution in ransomware tactics, building upon the foundational attack vectors and methods of its predecessors, MountLocker and Quantum. Unlike earlier strains, Dagon Locker employs a double-extortion model, where victims face not only data encryption but also threats to release stolen information unless a ransom is paid. The use of ChaCha20+RSA-2048 encryption indicates an attempt to balance computational efficiency with robust security, though this approach may leave vulnerabilities exploitable by determined adversaries. Initial access is facilitated through IcedID malware, which suggests a reliance on proven tools for compromising systems. Dagon Locker's operators exhibit moderate sophistication, leveraging existing frameworks like the IcedID botnet for distribution but lacking the complex operational security (OPSEC) measures seen in high-tier threat actors.

Key Capabilities

  • Leverages IcedID malware for initial access
  • Employs double extortion tactics with ChaCha20+RSA-2048 encryption
  • Deploys custom ransomware with encrypted payloads
  • Operates within the IcedID botnet framework
  • Uses phishing emails and malicious Office documents as attack vectors

MITRE ATT&CK Tactics

Execution
Discovery
Data Exfiltration
ransomware

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

IcedID RAT
Custom ransomware (double extortion)
Malicious script files (ChaCha20+RSA payloads)

Campaigns & Victims

Dagon Locker's campaign patterns remain largely undefined due to its recent emergence in early 2023. Its operators appear to focus on rapid deployment and financial gain, targeting systems with limited resistance to IcedID attacks. Notable past operations are not publicly documented, but the group's reliance on established attack frameworks suggests it may affiliate or collaborate with other ransomware operators. The use of double extortion indicates a shift toward more aggressive tactics compared to its predecessors.

IOC Patterns

  • Spear-phishing emails containing malicious Office documents
  • IcedID RAT activity indicating botnet compromise
  • Network traffic associated with IcedID C2 servers
  • Encrypted files using ChaCha20+RSA-2048 encryption

Recommended Actions

  • Implement robust email filtering and endpoint detection to block phishing attempts
  • Monitor for signs of IcedID activity on the network
  • Regularly back up critical systems and test backup recoverability
  • Train employees to recognize suspicious emails and attachments
  • Segment networks to limit ransomware lateral movement

Suggested Tags

ransomware
cybercrime
financial-motivation
double-extortion
IcedID

Confidence Assessment

The analysis of Dagon Locker is based on limited open-source intelligence, with most information derived from its technical lineage and known characteristics. Confidence in the data is moderate, as specific campaign details remain unclear. Information gaps include precise targeting criteria, long-term operational patterns, and geographic focus areas.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
cybercrime
financial-motivation
double-extortion
IcedID

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.