Dagon Locker is a ransomware strain that first appeared in early 2023, evolved from the MountLocker/Quantum ransomware lineage, and uses IcedID as an initial access vector before deploying double-extortion attacks with ChaCha20+RSA-2048 encryption. 1 ransom note(s) on file
Objectives
Executive Summary
Dagon Locker is a medium-sophistication ransomware strain linked to the MountLocker/Quantum lineage, utilizing IcedID for initial access and employing double extortion tactics through ChaCha20+RSA-2048 encryption. Its primary motivation is financial gain, targeting unspecified sectors with a focus on disrupting operations through data encryption. The group operates with moderate technical capabilities but has demonstrated adaptability by leveraging established ransomware infrastructure.
Goals & Targeting
Dagon Locker's strategic objectives revolve around financial gain through ransomware operations. It targets unspecified sectors, but its use of double extortion and encryption suggests a focus on industries with high data sensitivity and recovery costs. The group likely selects victims based on ease of access, system criticality, and potential for significant financial impact. Typical victims may include businesses reliant on IT infrastructure, such as healthcare, manufacturing, or logistics, where operational downtime could lead to substantial economic losses.
Enhanced Description
Dagon Locker represents an evolution in ransomware tactics, building upon the foundational attack vectors and methods of its predecessors, MountLocker and Quantum. Unlike earlier strains, Dagon Locker employs a double-extortion model, where victims face not only data encryption but also threats to release stolen information unless a ransom is paid. The use of ChaCha20+RSA-2048 encryption indicates an attempt to balance computational efficiency with robust security, though this approach may leave vulnerabilities exploitable by determined adversaries. Initial access is facilitated through IcedID malware, which suggests a reliance on proven tools for compromising systems. Dagon Locker's operators exhibit moderate sophistication, leveraging existing frameworks like the IcedID botnet for distribution but lacking the complex operational security (OPSEC) measures seen in high-tier threat actors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Dagon Locker's campaign patterns remain largely undefined due to its recent emergence in early 2023. Its operators appear to focus on rapid deployment and financial gain, targeting systems with limited resistance to IcedID attacks. Notable past operations are not publicly documented, but the group's reliance on established attack frameworks suggests it may affiliate or collaborate with other ransomware operators. The use of double extortion indicates a shift toward more aggressive tactics compared to its predecessors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis of Dagon Locker is based on limited open-source intelligence, with most information derived from its technical lineage and known characteristics. Confidence in the data is moderate, as specific campaign details remain unclear. Information gaps include precise targeting criteria, long-term operational patterns, and geographic focus areas.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics