Blue Locker Ransomware

A
Anonymous
10 months ago
290 views
26 nodes

This flow details the Blue Locker ransomware campaign targeting Pakistan's oil and gas sector through phishing emails with malicious attachments. The attack employs a PowerShell-based loader to establish persistence via registry modification, escalate privileges by bypassing UAC, and evade detection through obfuscation and timestomping techniques. The ransomware ultimately encrypts victim files with a '.Blue' extension after deleting system backups using WMIC commands.

React Flow mini map