MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions.
18Victims
Feb 6, 2021First Discovered
Feb 8, 2022Last Discovered
1545Days Inactive
0%Infostealer
0/1Sites Online
Top Sectors
Manufacturing9
Construction3
Transportation/Logistics2
Consumer Services1
Healthcare1
Business Services1
Financial Services1
Known Locations (1)
mountnewsokhwilx.onion
Tools Used
Exfiltration
MEGA, PrivatLab
Victims (18)
Dassault Falcon Jet
Manufacturing
Discovered: Feb 8, 2022 · Attack est.: Feb 8, 2022