Description Summary
WastedLocker is targeted ransomware developed by Evil Corp (Indrik Spider), the sanctioned Russian cybercriminal group behind the Dridex banking trojan and BitPaymer. It appeared in 2020 and was delivered via the SocGholish fake-browser-update framework, most famously in the July 2020 attack that disrupted Garmin. Because U.S. sanctions on Evil Corp deter ransom payment, the group repeatedly rebranded its encryptors (Hades, PhoenixLocker, PayloadBIN, Macaw) and at times used LockBit to disguise attribution.
Threat Actor
Evil Corp / Indrik Spider (sanctioned; leader Maksim Yakubets). Delivered via SocGholish fake updates.
Technical Indicators
Encryption Extension
.wasted / .<victimname>wasted (e.g. .garminwasted)
Encryption Algorithm
AES-256 (files) + RSA-4096 (key wrapping)
Ransom Note Name
<victimname>_info text note per file
Targeted Industries
Manufacturing, Technology, Media, Large enterprise (US-focused)
First Seen
May 2020
Last Seen
2020–2021 (rebranded to Hades/Macaw/others)
Geographical Location
United States, Western Europe
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 1 | T1189 | Drive-by Compromise (SocGholish fake updates) |
| Execution x 1 | T1059.001 | PowerShell |
| Defense Evasion x 2 | T1055 | Process Injection |
| T1562.001 | Disable or Modify Tools | |
| Privilege Escalation x 1 | T1548 | Abuse Elevation Control Mechanism (UAC bypass) |
| Credential Access x 1 | T1003 | OS Credential Dumping |
| Lateral Movement x 1 | T1021.002 | SMB/Windows Admin Shares |
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |