ATT&CKSoftwareLockerGoga

LockerGoga

S0372

Malware.View on attack.mitre.org

About this malware

LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including industrial and manufacturing firms.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1070.004
File Deletion

LockerGoga has been observed deleting its original launcher after execution.

T1486
Data Encrypted for Impact

LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key.

T1529
System Shutdown/Reboot

LockerGoga has been observed shutting down infected systems.

T1531
Account Access Removal

LockerGoga has been observed changing account passwords and logging off current users.

T1553.002
Code Signing

LockerGoga has been signed with stolen certificates in order to make it look more legitimate.

T1570
Lateral Tool Transfer

LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating.

T1685
Disable or Modify Tools

LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus.

Groups that use it1

Campaigns0

None recorded.

References2

  1. CarbonBlack LockerGoga 2019 Open source
    CarbonBlack Threat Analysis Unit. (2019, March 22). TAU Threat Intelligence Notification – LockerGoga Ransomware. Retrieved April 16, 2019.
  2. Unit42 LockerGoga 2019 Open source
    Harbison, M. (2019, March 26). Born This Way? Origins of LockerGoga. Retrieved April 16, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.