Mountlocker
Ransomware Group Profile
Overview
MountLocker operated as a ransomware-as-a-service from July 2020, using a standard developer/affiliate revenue split and leveraging compromised RDP credentials for initial access, propagating laterally via Windows Active Directory APIs and targeting over 2,600 file extensions.
Dark Web Infrastructure (1)
mountnewsokhwilx.onion
Activity Timeline
First SeenUnknown
Last SeenUnknown
Leak Sites1
Quick Actions