Active ransomware operator
← All groupsDagonlocker
aka QuantumLocker, Quantum, Mount Locker · 0 victims indexed · last activity 4 years ago
At a glance
- Status
- active
- Aliases
- QuantumLocker, Quantum, Mount Locker
- First seen
- —
- Last activity
- 4 years ago
- Onion sites
- 1 known endpoint
About
References
18 linksExternal sources curated by the MISP threat-intel community.
- malpedia.caad.fkie.fraunhofer.de/details/win.mount_locker
- securityscorecard.pathfactory.com/research/quantum-ransomware
- bleepingcomputer.com/news/security/mount-locker-ransomware-joins-the-multi-million-dollar-ransom-game/
- bleepingcomputer.com/news/security/mount-locker-ransomware-now-targets-your-turbotax-tax-returns/
- dissectingmalwa.re/between-a-rock-and-a-hard-place-exploring-mount-locker-ransomware.html
- blogs.blackberry.com/en/2020/12/mountlocker-ransomware-as-a-service-offers-double-extortion-capabilities-to-affiliates
- github.com/Finch4/Malware-Analysis-Reports/tree/master/MountLocker
- chuongdong.com/reverse%20engineering/2021/05/23/MountLockerRansomware/
- symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-virtual-machines
- kienmanowar.wordpress.com/2021/08/04/quicknote-mountlocker-some-pseudo-code-snippets/
- cybereason.com/blog/cybereason-vs.-quantum-locker-ransomware
- thedfirreport.com/2022/04/25/quantum-ransomware/
- ransomlook.io/group/quantum
- ransomlook.io/group/dagonlocker
- sentinelone.com/anthology/dagon-locker/
- asec.ahnlab.com/en/42037/
- broadcom.com/support/security-center/protection-bulletin/dagon-locker-ransomware
- mphasis.com/content/dam/mphasis-com/global/en/home/services/cybersecurity/icedid-infection-to-dagon-locker-ransomware-apr29-22-7.pdf
Recent victims
Loading…
Onion infrastructure
1 known- http://dgnh6p5uq234zry7qx7bh73hj5ht3jqisgfet6s7j7uyas5i46xfdkyd.onion
Source
Updated 4 years agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
