ATT&CKSoftwareSeth-Locker

Seth-Locker

S0639

Malware.View on attack.mitre.org

About this malware

Seth-Locker is a ransomware with some remote control capabilities that has been in use since at least 2021.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1059.003
Windows Command Shell

Seth-Locker can execute commands via the command line shell.

T1105
Ingress Tool Transfer

Seth-Locker has the ability to download and execute files on a compromised host.

T1486
Data Encrypted for Impact

Seth-Locker can encrypt files on a targeted system, appending them with the suffix .seth.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Trend Micro Ransomware February 2021 Open source
    Centero, R. et al. (2021, February 5). New in Ransomware: Seth-Locker, Babuk Locker, Maoloa, TeslaCrypt, and CobraLocker. Retrieved August 11, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.