LockNet
LockNet is a purported ransomware strain announced by the pro-Iranian hacktivist group DieNet. Reporting states that DieNet announced development of the “LockNet” ransomware platform and claimed it was used against UTLX, a Marmon Rail Company subsidiary in Chicago. However, the available content explicitly notes that this ransomware-use claim remains unverified. The broader reporting on DieNet characterizes the group primarily as a disruptive DDoS-focused and propaganda-oriented actor that relies on rented DDoS-as-a-service infrastructure rather than bespoke malware development, and emphasizes that many of its claims involving ransomware, data theft, OT/ICS access, and intrusion are exaggerated or unconfirmed. Based on the provided content, high-confidence attribution links LockNet only to DieNet’s public claims; no verified technical details, infection vector, platform specifics, persistence mechanisms, encryption behavior, ransom note details, or indicators of compromise are provided.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Locknet Ransomware DieNet announced “Locknet” as its own ransomware, allegedly used against UTLX, a Marmon Rail Company subsidiary in Chicago.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A purported ransomware strain announced by DieNet and allegedly used against UTLX; the claim remains unverified and is treated with skepticism in the content.
Announced (in-development) ransomware platform attributed to DieNet.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.