WhiteLock is a recently identified Windows ransomware family. It encrypts victim files, appends the .Fbin extension, creates a ransom note named c0ntact.Txt, and changes the desktop wallpaper after encryption. The malware communicates with external servers during execution, collects the victim device’s MAC address, hashes it with SHA-256 for identification, obtains an RSA public key from the server, generates a 32-byte AES key and 16-byte IV, uses AES-CBC to encrypt files, and protects the AES key with RSA-2048 before transmitting it to the external server. WhiteLock also checks for AnyDesk and TeamViewer and terminates related services to hinder remote response during encryption. Reported exclusions include folders such as $Recycle.Bin, \AppData, \ProgramData, \Windows, \System Volume Information, \Google, and \Windows\servicing; filenames such as c0ntact.Txt, DumpStack.Log.Tmp, pagefile.Sys, swapfile.Sys, hiberfil.Sys, desktop.ini, and ntuser.dat; already encrypted .Fbin files; and files matching keywords related to major antivirus and security products. The ransom note claims both file encryption and data theft, threatens to notify contacts, sell stolen information, and publish it on the dark web and internet if payment is not made, and directs victims to a Tor-based negotiation page. WhiteLock has been linked to intrusion chains in which information-stealing malware, specifically WezRat, was used before ransomware deployment. Multiple cited reports associate WhiteLock with Cotton Sandstorm, also tracked as Haywire Kitten and assessed in the content as affiliated with Iran’s IRGC, and state that it was deployed in some intrusions specifically against Israeli targets. High-confidence behavioral indicators mentioned in the content include mass file modification, creation of c0ntact.Txt ransom notes, abnormal external communications, termination of AnyDesk and TeamViewer services, encrypted files with the .Fbin extension, and wallpaper changes.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cotton Sandstorm deployed WezRat and WhiteLock alongside the Altoufan persona for hack-and-leak amplification.
...attacks using ‘WhiteLock’ ransomware, deployed after WezRat infostealer.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
WhiteLock ransomware encrypts key files on Windows systems and then generates a ransom note demanding payment.
WhiteLock searches for and terminates AnyDesk and TeamViewer-related services.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that encrypts key files on Windows systems and generates a ransom note demanding payment; it also communicates with external servers.
Ransomware that encrypts files on Windows systems, appends the .Fbin extension, creates a c0ntact.Txt ransom note, communicates with external servers during encryption, terminates AnyDesk and TeamViewer services to hinder remote response, and uses AES-CBC with RSA-2048 key protection.
A backdoor or access tool reportedly pre-positioned by Cotton Sandstorm before the February 28 strikes.
Malware deployed by Cotton Sandstorm alongside WezRat for hack-and-leak amplification.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.