Loki Locker is a Ransomware-as-a-Service (RaaS) variant that first emerged in mid-2021, primarily targeting Windows personal computers and English-speaking victims . It operates using a limited network of affiliates and is known for encrypting files and demanding cryptocurrency ransoms . A distinguishing feature of Loki Locker is its optional wiper functionality, which can delete all non-system files and overwrite the Master Boot Record if ransom demands are not met within a specified timeframe, typically 30 days, thereby rendering the compromised system unusable . The malware's code is obfuscated using commercial and open-source protectors, complicating analysis and detection . While some analyses suggest potential Iranian links through false flag tactics, the definitive origin of the group remains unconfirmed . Its core motivation is financial gain through illicit operations .