Mount Locker
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
Mount Locker is a ransomware group tracked under that alias, with open‑source reporting indicating the actors operate from Russia. The group first appeared in mid‑2020 when it began breaching corporate networks to exfiltrate data before deploying its ransomware payload. Mount Locker’s malware combines ChaCha20 stream cipher encryption with RSA‑2048 for key protection, a combination that currently leaves no free decryption option for victims. After encryption, the actors threaten to publish stolen data on a dedicated leak site unless a ransom is paid, a double‑extortion tactic seen in several of their attacks. Their ransom notes have demanded multi‑million dollar payments, and in one case they asked for two billion dollars from a United Kingdom‑based infrastructure services firm.
Mount Locker has shown a pattern of targeting organizations that provide essential services or handle sensitive information. In early 2021 the group encrypted systems at a Canadian public school board, causing widespread service disruption while asserting that no personal data had been compromised. Late in 2020 they struck a United Kingdom waste‑management and street‑cleaning contractor, exfiltrating 143 GB of contracts, passports and financial records before publishing the material on their leak site. Around the same period they attacked a biomedical research firm involved in COVID‑19 vaccine development, stealing approximately 150 GB of research data and releasing a portion as proof of the breach. Across these incidents the actors’ primary goal appears to be financial gain through ransom demands, although the encryption inevitably disrupts the victims’ operations.
While Mount Locker operates independently, there have been observations of loose cooperation with other ransomware actors; for example, Conti threat actors publicly pointed journalists toward the Mount Locker leak of the UK contractor’s data, though Conti stated they were not directly involved in the intrusion. No public evidence links the group to a state sponsor or to a larger criminal consortium beyond these occasional information‑sharing interactions. The group's known activity spans late 2020 through at least early 2021, with the school‑board, waste‑management and biotech incidents serving as representative examples of its operational style. These cases illustrate Mount Locker’s reliance on data theft followed by ransomware deployment and its focus on high‑value targets capable of paying large sums.
Incidents
Attributed incidents are available to members.
3 incidents