Recent discoveries of variants of LockerGoga, a type of ransomware that targets industrial systems, have demonstrated that ransom payments appear to be an aspect and not the true purpose of this particular malware.

The malware was recently found at the center of an attack on Norsk Hydro. The aluminum producer was infected with a strain of the malware that locked its systems and demanded a ransom. This demand was not met.
Instead, Norsk Hydro asked for help and Microsoft, among others, responded.
However, the company was forced to switch to manual processes and was unable to access customer orders until backups were restored.
LockerGoga is one of several types of malware that have attacked industrial systems. Similar to it is Industroyer, malware that ESET says is “specifically designed for attacks on the power grid” and was responsible for temporarily shutting down the power grid in Kiev, Ukraine, in 2016.
According to researchers at Securonix Threat Research, the LockerGoga variants provided a first glimpse into the malware's capabilities – as well as some strange programming elements that make it difficult to pay the ransom.
In a publication on Tuesday, Securonix published a detailed report on the capabilities of LockerGoga exploits currently in operation.
The LockerGoga infection vector has not been verified, but in many cases of enterprise infections, it is likely that phishing emails represent the initial stage of infection. Researchers say that Microsoft Word or RTF files containing embedded, malicious macros are quite suspicious.
The malicious files are signed with valid certificates that allow them to bypass traditional security measures. The ransomware uses multiple certificate authorities (CAs) to sign the software – Alisa Ltd., Kitty Ltd, Sectigo and Mikl Limited – and some variants of the malware are equipped with taskkill capabilities to disable antivirus systems. Others are also capable of deleting even Windows processes.
Once a system is infected with LockerGoga, some processes will move malicious files over the network using the Microsoft Server Message Block (SMB) protocol, while others have been observed using Active Directory management services for the same purposes.
The malware then begins its operations. LockerGoga focuses on encrypting files with popular extensions, such as .doc, .xml, .ppt, and .pdf files using AES-256 keys and then using the *.LOCKED extension.
The primary purpose of the malware is to infect and encrypt. However, some LockerGoga variants contain strange programming that can make it difficult for its victims to pay the ransom.
In some cases, the malware will change administrator passwords and lock victims out of their system using logoff.exe.
Oleg Kolesnikov, Director of Threat Research at Securonix, said:
“One of the reasons LockerGoga was so aggressive against Norsk Hydro was the size of the company. Infecting multiple systems by copying the ransomware to the shared directory affected the entire organization.”
