MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions. Known victims: 18
Objectives
Executive Summary
MountLocker is a medium-sophistication criminal ransomware-as-a-service (RaaS) group operational since July 2020. Primarily motivated by financial gain, MountLocker targets over 2,600 file extensions using compromised RDP credentials and lateral movement via Windows Active Directory APIs, making them a significant threat to sectors with exposed RDP services.
Goals & Targeting
MountLocker's primary objectives are financial gain through ransomware deployments. They target organizations with exposed or weakly secured RDP services, leveraging lateral movement capabilities via AD APIs to maximize encryption impact. Their targeting is not sector-specific but tends to focus on entities where data value and RDP exposure create higher opportunities for successful campaigns.
Enhanced Description
MountLocker emerged as a notable ransomware group in 2021, operating under the RaaS model. Their campaigns typically involve initial access via compromised RDP credentials, followed by lateral movement using Windows Active Directory APIs for propagation. Over 2,600 file types are targeted, indicating a broad focus on data encryption across various industries. MountLocker's use of RDP access and AD enumeration suggests a methodical approach to network compromise and data exfiltration, emphasizing their technical proficiency within the criminal ransomware landscape.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Campaigns & Victims
MountLocker's campaigns often involve initial RDP compromise, followed by lateral movement within networks using AD APIs. Their activities are characterized by high-volume file encryption targeting critical data types. Notable for their longevity and adaptability in a changing ransomware landscape.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence based on known TTPs and operational timeframe. Limited direct intelligence links to specific tools or techniques.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics