WastedLocker Ransomware
WastedLocker is a newly observed ransomware tool believed to have been created but the TA505 advanced persistent threat group for use in their own campaigns.
Summary
WastedLocker is a newly observed ransomware tool believed to have been created but the TA505 advanced persistent threat group for use in their own campaigns.
Affected platforms
The following platforms are known to be affected:
Threat details
As with other TA505 tools, WastedLocker is delivered via fake software updates displayed on compromised sites using the Domen exploit kit. When a user interacts with one of these sites a Cobalt Strike payload is delivered to act as an initial foothold on the target network. TA505 then use this foothold to propagate across the network before deploying WastedLocker.
Once delivered, WastedLocker will attempt to Doppelpaymer, WastedLocker does not appear to extract data before encryption
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting files, which may also include remote files on network locations. The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. To reduce the likelihood of infection by ransomware, NHS Digital advises that:
Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages. To limit the impact of a ransomware infection, NHS Digital advises that:
|
Indicators of compromise
Last edited: 10 January 2022 2:57 pm