monolock
0 incidentes
0 paises
0 sectores
ransomware Ultimo: -
Monolock emerged in late September 2025 as a commercially available ransomware-as-a-service (RaaS) offering on dark web forums. Its primary motivation is financial gain through the encryption and exfiltration of victim data. This group distinguishes itself by offering tiered access levels for affiliates and features multi-threaded AES-256 encryption, support for both Windows and Linux environments, and a command and control framework written in GoLang. Unique aspects include an automatic torrent-based distribution feature for lateral spread and claimed compatibility with cloud storage services such as AWS S3 and Google Cloud Storage. The group operates solely under the name Monolock, with no known aliases or common confusions with other threat actors.
Paises objetivo (OSINT)
Australia
United Kingdom
United States
Sectores objetivo (OSINT)
ConstructionManufacturingFinanceProfessional&Technical ServicesHealthCare & Social AssistanceOther