WastedLocker Ransomware

Description Summary

WastedLocker is targeted ransomware developed by Evil Corp (Indrik Spider), the sanctioned Russian cybercriminal group behind the Dridex banking trojan and BitPaymer. It appeared in 2020 and was delivered via the SocGholish fake-browser-update framework, most famously in the July 2020 attack that disrupted Garmin. Because U.S. sanctions on Evil Corp deter ransom payment, the group repeatedly rebranded its encryptors (Hades, PhoenixLocker, PayloadBIN, Macaw) and at times used LockBit to disguise attribution.

Threat Actor

Evil Corp / Indrik Spider (sanctioned; leader Maksim Yakubets). Delivered via SocGholish fake updates.

Technical Indicators

Encryption Extension
.wasted / .<victimname>wasted (e.g. .garminwasted)
Encryption Algorithm
AES-256 (files) + RSA-4096 (key wrapping)
Ransom Note Name
<victimname>_info text note per file
Targeted Industries
Manufacturing, Technology, Media, Large enterprise (US-focused)
First Seen
May 2020
Last Seen
2020–2021 (rebranded to Hades/Macaw/others)
Geographical Location
United States, Western Europe

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 1 T1189 Drive-by Compromise (SocGholish fake updates)
Execution x 1 T1059.001 PowerShell
Defense Evasion x 2 T1055 Process Injection
T1562.001 Disable or Modify Tools
Privilege Escalation x 1 T1548 Abuse Elevation Control Mechanism (UAC bypass)
Credential Access x 1 T1003 OS Credential Dumping
Lateral Movement x 1 T1021.002 SMB/Windows Admin Shares
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery