NailaoLocker is a ransomware family observed in targeted intrusions, including campaigns against European organizations and notably entities in the healthcare sector. It has been associated with post-compromise activity involving the PlugX and ShadowPad backdoors, and reporting has linked some intrusions to exploitation of CVE-2024-24919 in Check Point gateway and VPN environments before ransomware deployment. Activity clusters associated with Chinese intrusion tooling and tradecraft have overlapped with campaigns that delivered NailaoLocker, and some assessments have suggested the ransomware may in certain cases have been used to obscure broader espionage objectives under the cover of extortion.
Technically, NailaoLocker encrypts files using multi-threaded AES-256-CBC routines and appends a distinct encrypted-file extension while dropping customized HTML ransom notes. It excludes system-critical files and directories to preserve host stability during encryption. The malware has been documented using the Chinese SM2 elliptic-curve standard to protect per-file or session encryption material. Analysts have also noted an embedded decryption routine that appears nonfunctional in observed samples, an unusual characteristic for ransomware that may indicate incomplete development or deliberate misdirection.
Execution has been tied to DLL side-loading, in which a legitimate signed executable loads a malicious DLL that decrypts and launches the core ransomware payload. NailaoLocker creates a mutex to prevent duplicate execution, attempts to remove loader artifacts after launch, records activity to a local log, and hides encrypted files, reflecting both operational control and defense-evasion behavior. The family is primarily documented on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Two years ago, the cybersecurity agency flagged another flaw (CVE-2024-24919) in Check Point's Quantum Security Gateways as actively exploited by ransomware gangs, confirming an Orange Cyberdefense CERT report linking it to NailaoLocker ransomware attacks.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Persistence and stealth are enhanced by mutex creation (Global\lockv7) to avoid re-execution, and the malware attempts to clean up after itself by deleting the loader DLL post-infection.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family linked to exploitation of Check Point Quantum Security Gateways vulnerability CVE-2024-24919, mentioned as historical background.
A ransomware family tied to exploitation of Check Point Quantum Security Gateways, with distribution involving ShadowPad and PlugX backdoors.
Ransomware linked to exploitation of Check Point Quantum Security Gateways vulnerability CVE-2024-24919.
Ransomware family referenced as an associated analytic story for detection of common ransomware file extensions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.