XingLocker is a ransomware group using a MountLocker-based RaaS model and IcedID to spread across enterprise networks.
Analyst brief
XingLocker is a ransomware group using a franchise-style RaaS model based on MountLocker payloads. They primarily target enterprise networks, gaining initial access through IcedID and employing worm-style lateral movement via Windows Active Directory APIs. Defenders should prioritize early detection of IcedID infections and monitor for lateral movement patterns.
xinglocker
crime
XingLocker is a ransomware group that emerged in May 2021 as part of a franchise-style RaaS model built on a customized MountLocker payload, using IcedID for initial access and Windows Active Directory APIs for worm-style lateral movement across networks.