Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors xinglocker

Description

XingLocker is a ransomware group that emerged in May 2021 as part of a franchise-style RaaS model built on a customized MountLocker payload, using IcedID for initial access and Windows Active Directory APIs for worm-style lateral movement across networks. Known victims: 21

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 months ago

Executive Summary

XingLocker is a medium-sophistication ransomware group operating under a franchise-style RaaS model, using customized MountLocker payloads for financial gain. First seen in April 2021, they target organizations for ransom, leveraging IcedID for initial access and Windows Active Directory APIs for lateral movement. Their primary motivation is organizational gain through financial extortion.

Goals & Targeting

XingLocker's strategic objectives are centered around achieving financial gain through ransomware extortions, targeting organizations that are likely to pay significant ransoms to restore critical data and services. Their targeting profile suggests a focus on sectors and countries with high-value targets, aiming to maximize potential payouts. Typical victims include organizations with critical data and those who are likely to succumb to ransom demands to minimize downtime and reputational damage.

Enhanced Description

The operational tempo and tactics employed by XingLocker highlight the evolving nature of ransomware threats. By leveraging existing malware strains like IcedID and combining them with customized payloads and lateral movement techniques, groups like XingLocker underscore the complexities faced by defenders. The use of Windows Active Directory APIs for lateral movement, in particular, emphasizes the importance of robust network segmentation and access control measures to mitigate the spread of such threats.

Key Capabilities

  • Customized ransomware payloads
  • Lateral movement within networks
  • Use of IcedID for initial access
  • Windows Active Directory API exploitation
  • Franchise-style RaaS operations

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1190
T1204
T1218
T1566.001
T1059.003

Software / Tooling

IcedID
Customized MountLocker
Ransomware

Campaigns & Victims

XingLocker's campaign patterns indicate a focus on rapid initial access and lateral movement to compromise high-value targets, with the goal of extorting significant ransoms. Their operational tempo is characterized by the use of existing malware strains and customized payloads, suggesting a modular and adaptable approach to their operations. Notable past operations include the targeting of at least 21 organizations, with a temporal spread between April and October 2021, indicating a consistent and evolving threat posture.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • Use of IcedID for initial access
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Windows Active Directory API exploitation

Recommended Actions

  • Implement robust email filtering and employee education on spear-phishing
  • Enforce strict network segmentation and access controls
  • Regularly update and patch Windows Active Directory APIs
  • Deploy advanced threat detection and response tools
  • Develop and regularly test ransomware response plans

Suggested Tags

Ransomware
Financially motivated crime
Customized malware
Franchise-style RaaS

Confidence Assessment

The confidence level in the available data on XingLocker is medium, given the specific details on their operational tactics and the use of customized payloads. However, information gaps exist regarding their full spectrum of targeted sectors and countries, as well as the entirety of their technical capabilities and the scope of their past operations. Further intelligence gathering is necessary to completely understand their threat posture and potential future evolutions.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financially motivated crime
Customized malware
Franchise-style RaaS

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 29, 2021
Last Seen
Oct 26, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.