Skip to content

mountlocker

Inactive

0 tracked victims · First seen Feb 7, 2021 · Last seen Feb 8, 2022

About

Aggregated threat-intel description

MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions.

Recent victims

View all →
No recent victims.

All ransomware groups · Dark web intelligence