Dagon Locker is a ransomware group evolved from MountLocker lineage, known for double-extortion attacks.
Analyst brief
Dagon Locker is a ransomware group evolved from the MountLocker/Quantum ransomware lineage, first seen in early 2023. It uses IcedID as an initial access vector. Key TTPs include double-extortion attacks employing ChaCha20 + RSA-2048 encryption. Defenders should focus on detecting IcedID loaders and reinforcing backup strategies against extortion phases.
dagonlocker
crime
Dagon Locker is a ransomware strain that first appeared in early 2023, evolved from the MountLocker/Quantum ransomware lineage, and uses IcedID as an initial access vector before deploying double-extortion attacks with ChaCha20+RSA-2048 encryption.