Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors mountlocker

Description

MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions. Known victims: 18

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

MountLocker is a medium-sophistication criminal ransomware-as-a-service (RaaS) group operational since July 2020. Primarily motivated by financial gain, MountLocker targets over 2,600 file extensions using compromised RDP credentials and lateral movement via Windows Active Directory APIs, making them a significant threat to sectors with exposed RDP services.

Goals & Targeting

MountLocker's primary objectives are financial gain through ransomware deployments. They target organizations with exposed or weakly secured RDP services, leveraging lateral movement capabilities via AD APIs to maximize encryption impact. Their targeting is not sector-specific but tends to focus on entities where data value and RDP exposure create higher opportunities for successful campaigns.

Enhanced Description

MountLocker emerged as a notable ransomware group in 2021, operating under the RaaS model. Their campaigns typically involve initial access via compromised RDP credentials, followed by lateral movement using Windows Active Directory APIs for propagation. Over 2,600 file types are targeted, indicating a broad focus on data encryption across various industries. MountLocker's use of RDP access and AD enumeration suggests a methodical approach to network compromise and data exfiltration, emphasizing their technical proficiency within the criminal ransomware landscape.

Key Capabilities

  • Compromise of RDP credentials
  • Windows Active Directory lateral movement
  • Broad file extension targeting

MITRE ATT&CK Tactics

Attack Preparation & Exploitation
Credential Access

ATT&CK Techniques

T1072.001
T1566.001

Campaigns & Victims

MountLocker's campaigns often involve initial RDP compromise, followed by lateral movement within networks using AD APIs. Their activities are characterized by high-volume file encryption targeting critical data types. Notable for their longevity and adaptability in a changing ransomware landscape.

IOC Patterns

  • RDP brute-force attempts
  • Unusual Active Directory queries

Recommended Actions

  • Hardening RDP access with multi-factor authentication
  • Monitoring for AD enumeration activity

Suggested Tags

apt
ransomware

Confidence Assessment

Moderate confidence based on known TTPs and operational timeframe. Limited direct intelligence links to specific tools or techniques.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
apt
ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 7, 2021
Last Seen
Feb 8, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.