AdminLocker is a low-profile ransomware targeting individual users and demanding Bitcoin ransom via Tor portals.
Analyst brief
AdminLocker is a low-profile ransomware first observed in December 2021, operated by a lone actor or a small closed group with no evidence of an affiliate model. It primarily targets individual users and small businesses, encrypting files and demanding Bitcoin ransom via a Tor-based portal. Defenders should focus on regular system backups, multi-factor authentication, and network segmentation to counter initial access attempts typically leveraged through suspicious email attachments or weak RDP configurations.
adminlocker
crime
AdminLocker is a relatively low-profile ransomware strain first observed around December 2021, encrypting victim files and demanding Bitcoin ransom via a Tor-based portal, operated by a lone actor or small closed group with no evidence of an affiliate model.
What is AdminLocker ransomware and who are its primary targets?+
AdminLocker is a low-profile ransomware first observed in December 2021, operated by a lone actor or small closed group. It primarily targets individual users and small businesses.
What defensive measures should be taken against AdminLocker?+
Defenders should focus on regular system backups, multi-factor authentication (MFA), and network segmentation to counter initial access attempts typically leveraged through suspicious email attachments or weak RDP configurations.