HomeSecurityHackers sell Monolock Ransomware on Dark Web forums

Hackers are selling Monolock Ransomware on Dark Web forums

Monolock ransomware has appeared on underground forums, with hackers advertising version 1.0 for sale along with stolen corporate credentials.

See also: AI-powered ransomware attacks: The top security concern

Monolock ransomware

The malware was first detected in late September and exploits phishing emails containing malicious Word documents.

Once opened, the embedded macro downloads the ransomware binary from a compromised server. Victims report file encryption using a mix of AES-256 for file payloads and RSA-2048 for key exchange, making data inaccessible without the private key.

Dark Web Informer analysts noted that initial deployments of Monolock ransomware targeted small to medium-sized organizations in the healthcare and manufacturing sectors. The providers demand payment in cryptocurrency, instructing victims to access a Tor-hosted payment gateway. This gateway automatically verifies the transaction and provides the decryption key.

Early samples reveal a ransom note offering a 10% discount if paid within 48 hours.

In controlled environments, researchers have observed that Monolock ransomware terminates processes associated with common backup and security software before encryption begins. It scans running services for patterns matching “backup,” “sql,” and “vss,” and then terminates them to prevent snapshot restores.

See also: Microsoft revokes 200 certificates used in ransomware attacks

Hackers are selling Monolock Ransomware on Dark Web forums

After encryption, it adds the “.monolock” extension to the file names and leaves a ransom note named “README_RECOVER.txt” in each directory.

The infection mechanism of Monolock ransomware is embedded in the Windows registry under the Run key, ensuring execution at startup. The malware binary is disguised as a legitimate DLL and injected into explorer.exe to evade detection. It uses hashing API to dynamically identify required Windows functions, complicating static signature matching.

A snippet of the API hash routine demonstrates this tactic:

DWORD hash = 0xA1B2C3D4; for (char* p = moduleName; *p; ++p) { hash = ((hash << 7) | (hash >> (32 – 7))) ^ *p; }

By exploiting this routine, Monolock ransomware avoids injecting functions by name, blocking many endpoint detection tools.

See also: Hackers use 'Velociraptor' in ransomware attacks

Hackers are selling Monolock Ransomware on Dark Web forums

This advanced evasion highlights the need for behavioral-based monitoring to detect such threats.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS