ChileLocker is a global ransomware group operating under RaaS model on criminal forums.
Analyst brief
ChileLocker (also tracked as ARCrypter) is a ransomware group that emerged in August 2022 after attacking a Chilean government agency and has since expanded globally. It primarily targets the government sector and various organizations, operating under a Ransomware-as-a-Service (RaaS) model via criminal forums. Encrypted files are appended with a ".crypt" extension. Defenders should be vigilant against multiple initial access vectors due to its RaaS nature, enforce application whitelisting, and monitor for file encryption activity leading to ".crypt" extensions.
chilelocker
crime
ChileLocker (also known as ARCrypter) first appeared in August 2022 after attacking a Chilean government agency and quickly expanded globally, appending a ".crypt" extension to encrypted files and recruiting affiliates under a RaaS model on criminal forums.
What distinct extension is known to be appended to files encrypted by the ChileLocker ransomware group?+
ChileLocker (ARCrypter) appends a ".crypt" extension to encrypted files. Defenders are advised to specifically monitor for file encryption activity involving this extension.
What sector does ChileLocker primarily target and how does it expand its operations?+
ChileLocker primarily targets the government sector and various organizations. It expands its operations by recruiting affiliates under a Ransomware-as-a-Service (RaaS) model on criminal forums.