ATT&CKReferencesUnit42 LockerGoga 2019

Unit42 LockerGoga 2019

Harbison, M. (2019, March 26). Born This Way? Origins of LockerGoga. Retrieved April 16, 2019.

Open the source

Techniques2

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
MalwareLockerGoga

LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key.

T1531
Account Access Removal
MalwareLockerGoga

LockerGoga has been observed changing account passwords and logging off current users.

T1570
Lateral Tool Transfer
MalwareLockerGoga

LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.