ATT&CKReferencesCarbonBlack LockerGoga 2019

CarbonBlack LockerGoga 2019

CarbonBlack Threat Analysis Unit. (2019, March 22). TAU Threat Intelligence Notification – LockerGoga Ransomware. Retrieved April 16, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1070.004
File Deletion
MalwareLockerGoga

LockerGoga has been observed deleting its original launcher after execution.

T1486
Data Encrypted for Impact
MalwareLockerGoga

LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key.

T1531
Account Access Removal
MalwareLockerGoga

LockerGoga has been observed changing account passwords and logging off current users.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.