Netskope Threat Labs

MountLocker

ATP Sandbox Adv. HeuristicsAV

MountLocker is a ransomware as a service operation active since July 2020. Its encryptor uses ChaCha20 for file encryption with RSA-2048 protected keys, and while there are no trivial weaknesses allowing key recovery, its key generation method is cryptographically weak enough that researchers assessed it may be prone to attack. An update in November 2020 broadened its file type targeting and added security software evasion.

First seen
March 2022
Last seen
October 2026
Mountlocker
Alert Name
Gen:Variant.Ransom.MountLocker.26
Gen:Variant.Ransom.MountLocker.7
Gen:Variant.Ransom.MountLocker.8
Win32.Ransomware.Mountlocker
Win32.Ransomware.MountLocker
Win64.Ransomware.Mountlocker
Win64.Ransomware.MountLocker