MountLocker is a ransomware-as-a-service group active since 2020, targeting corporate networks.
Analyst brief
MountLocker is a ransomware-as-a-service group active since July 2020. They primarily target corporate networks, especially Windows Active Directory environments. Key TTPs include gaining initial access via compromised RDP credentials, propagating laterally through Windows Active Directory APIs, and encrypting over 2,600 file extensions. Defenders should focus on enforcing multi-factor authentication for RDP, monitoring for anomalous lateral movement activity, and maintaining offline backups of critical data.
mountlocker
crime
MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions.