Netskope Threat Labs

LokiLocker

ATP Sandbox Adv. HeuristicsAV

LokiLocker is a .NET ransomware first seen in August 2021. Its authors protected the malware with NETGuard, a modified ConfuserEX obfuscator using the KoiVM virtualization plugin, which complicates analysis of the encryptor. BlackBerry observed victims scattered around the world, with the main concentration in Eastern Europe and Asia.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Ransomware.LokiLocker
Gen:Variant.LokiLocker.1
Gen:Variant.Ransom.LokiLocker.1
Gen:Variant.Ransom.LokiLocker.11
Gen:Variant.Ransom.LokiLocker.23
Gen:Variant.Ransom.LokiLocker.24
Gen:Variant.Ransom.LokiLocker.28
Trojan.Ransom.LokiLocker.B
Win32.Ransomware.LokiLocker