Netskope Threat Labs

MarioLocker

ATP Sandbox Adv. Heuristics

MarioLocker is a ransomware variant that encrypts files on infected systems and demands payment for decryption. Its operators gain access through compromised credentials and remote services, and its encryption routine locks documents and data with strong cryptography while leaving a ransom demand. Researchers analyzed the family's behavior and remediation options.

First seen
October 2023
Last seen
October 2026
Alert Name
Linux.Ransomware.MarioLocker
Linux.Trojan.MarioLocker
Win64.Trojan.MarioLocker