ATT&CKSoftwareWastedLocker

WastedLocker

S0612

Malware.View on attack.mitre.org

About this malware

WastedLocker is a ransomware family attributed to Indrik Spider that has been used since at least May 2020. WastedLocker has been used against a broad variety of sectors, including manufacturing, information technology, and media.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1012
Query Registry

WastedLocker checks for specific registry keys related to the UCOMIEnumConnections and IActiveScriptParseProcedure32 interfaces.

T1027.013
Encrypted/Encoded File

The WastedLocker payload includes encrypted strings stored within the .bss section of the binary file.

T1027.016
Junk Code Insertion

WastedLocker contains junk code to increase its entropy and hide the actual code.

T1059.003
Windows Command Shell

WastedLocker has used cmd to execute commands on the system.

T1083
File and Directory Discovery

WastedLocker can enumerate files and directories just prior to encryption.

T1106
Native API

WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload.

T1112
Modify Registry

WastedLocker can modify registry values within the Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry key.

T1120
Peripheral Device Discovery

WastedLocker can enumerate removable drives prior to the encryption process.

T1135
Network Share Discovery

WastedLocker can identify network adjacent and accessible drives.

T1140
Deobfuscate/Decode Files or Information

WastedLocker's custom cryptor, CryptOne, used an XOR based algorithm to decrypt the payload.

T1222.001
Windows Permissions

WastedLocker has a command to take ownership of a file and reset the ACL permissions using the takeown.exe /F filepath command.

T1486
Data Encrypted for Impact

WastedLocker can encrypt data and leave a ransom note.

T1490
Inhibit System Recovery

WastedLocker can delete shadow volumes.

T1497.001
System Checks

WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique.

T1543.003
Windows Service

WastedLocker created and established a service that runs until the encryption process is complete.

View all 20 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. NCC Group WastedLocker June 2020 Open source
    Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021.
  2. Sentinel Labs WastedLocker July 2020 Open source
    Walter, J.. (2020, July 23). WastedLocker Ransomware: Abusing ADS and NTFS File Attributes. Retrieved September 14, 2021.
  3. Symantec WastedLocker June 2020 Open source
    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.