Uptime Hamster: 21d 12h 1mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Loki Locker

Loki Locker

0 incidentes 0 paises 0 sectores ransomware IR Ultimo: -
Ver en IntelTracker → APTTrail →
Loki Locker is a Ransomware-as-a-Service (RaaS) variant that first emerged in mid-2021, primarily targeting Windows personal computers and English-speaking victims . It operates using a limited network of affiliates and is known for encrypting files and demanding cryptocurrency ransoms . A distinguishing feature of Loki Locker is its optional wiper functionality, which can delete all non-system files and overwrite the Master Boot Record if ransom demands are not met within a specified timeframe, typically 30 days, thereby rendering the compromised system unusable . The malware's code is obfuscated using commercial and open-source protectors, complicating analysis and detection . While some analyses suggest potential Iranian links through false flag tactics, the definitive origin of the group remains unconfirmed . Its core motivation is financial gain through illicit operations .

Actores similares

medusalockerthreat-actor · 26tridentlockerthreat-actor · 6alphalockerthreat-actor · 3avoslockerthreat-actor · 3chilelockerthreat-actor · 3GDLockerSecthreat-actor · 2adminlockerthreat-actor · 2bluelockerthreat-actor · 2dagonlockerthreat-actor · 2flockerthreat-actor · 2
Tecnicas MITRE
T1189, T1204.002, T1566.001, T1059.001, T1566.002, T1190
Tipo
ransomware
Pais origen
IR
Motivacion
-
Impacto
54
Actualizado
Sat, 20 Ju

Paises objetivo (OSINT)

ArgentinaBrazilCanadaChileChinaColombiaSpainUnited KingdomIndiaItaly

Sectores objetivo (OSINT)

Enterprises & HoldingManufacturingConstructionPublic AdministrationOil & GasEducational ServicesWholesale TradeSpace & DefenseEnergy & Utilities Justice, Public Order, and Safety Activities