Skip to main content

Operator dossier

zerolockersec is a ransomware operator no longer publishing new disclosures. Darkfield has indexed 2 public victims claimed by this operator between March 25, 2025. ZeroLockerSec is a ransomware group first observed in March 2025 with apparent financial motivation, though its limited operational history makes comprehensive attribution difficult. Based on currently available public data, the group has claimed responsibility for at least one known victim, with targeting patterns indicating a focus on the United Arab Emirates. Given the group's very recent emergence and minimal victim count, no detailed technical analysis of their attack methodology, tooling, encryption implementation, or extortion tactics has been documented by CISA, the FBI, Mandiant, or other reputable threat intelligence sources as of this writing. No country of origin, threat actor affiliation, or Ransomware-as-a-Service infrastructure has been publicly attributed to the group, and no notable high-profile campaigns or law enforcement actions against them have been recorded. ZeroLockerSec should be considered an emerging and nascent threat actor whose operational capabilities, persistence, and true scope remain unassessed pending further intelligence collection; organizations operating in the UAE and the broader Gulf region should monitor for updated reporting as the group's activity develops.

Most-affected countries

Recent disclosures by zerolockersec

Most recent 1 of 2 indexed disclosures. Click any row for the full per-victim dossier.

See every disclosure indexed for zerolockersec

How we know this. Operator profiles on Darkfield are built from continuous monitoring of every leak site the group is known to operate, cross-correlated with community-curated feeds (RansomLook, ransomware.live, RansomWatch, MISP-galaxy). Status flips from active to inactive when no new disclosure appears for 60 days. MITRE ATT&CK mappings shown in the interactive section below are sourced from CISA, vendor analysis, and the MITRE community catalog — we attribute each technique back to its source. Aliases reflect operator re-brands and affiliate splits.

Inactive ransomware operator

All groups

zerolockersec

2 victims indexed · first seen 1 year ago · last activity 1 year ago

2
Victims indexed
#304 of 374 tracked operators
<1m
Active period
Mar 2025 → Mar 2025
1
Countries hit
top AE · 1

At a glance

Status
inactive
First seen
1 year ago
Last activity
1 year ago

About

ZeroLockerSec is a ransomware group first observed in March 2025 with apparent financial motivation, though its limited operational history makes comprehensive attribution difficult. Based on currently available public data, the group has claimed responsibility for at least one known victim, with targeting patterns indicating a focus on the United Arab Emirates. Given the group's very recent emergence and minimal victim count, no detailed technical analysis of their attack methodology, tooling, encryption implementation, or extortion tactics has been documented by CISA, the FBI, Mandiant, or other reputable threat intelligence sources as of this writing. No country of origin, threat actor affiliation, or Ransomware-as-a-Service infrastructure has been publicly attributed to the group, and no notable high-profile campaigns or law enforcement actions against them have been recorded. ZeroLockerSec should be considered an emerging and nascent threat actor whose operational capabilities, persistence, and true scope remain unassessed pending further intelligence collection; organizations operating in the UAE and the broader Gulf region should monitor for updated reporting as the group's activity develops.

Timeline

1 months
2025-03-01T00:00:00+00:00 · 1
2025-03-01T00:00:00+00:002025-03-01T00:00:00+00:00

Top countries

🇦🇪 United Arab Emirates
1

MITRE ATT&CK

1 techniques · 1 tactics

Tactics

Impact

Techniques

  • T1486Data Encrypted for Impact

Recent victims

Loading…

Source

Updated 1 year ago

Data on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.

Get alerted the next time zerolockersec posts a victim.

Add zerolockersec to your watchlist — Pro pings you within 5 minutes of any new zerolockersec leak-site post, Telegram callout, or affiliate-rebrand inference.