---
title: "Ransomware Resource: Security Primer on LockerGoga"
description: LockerGoga ransomware update. This is how the ransomware variant behaves and how you can mitigate the ransomware risk.
---

[SecureWorld News ](https://www.secureworld.io/industry-news)

# [Ransomware Resource: Security Primer on LockerGoga](https://www.secureworld.io/industry-news/ransomware-behavior-locker-goga)

 Written by [SecureWorld News Team](https://www.secureworld.io/industry-news/author/secureworld-news-team) | Tue | Apr 2, 2019 | 2:13 PM Z

If you're a regular reader, then you know we love to share resources that help cybersecurity leaders and teams (that is, you) keep organizations secure.

It's the reason SecureWorld recently wrote about a growing list of [free ransomware decryption keys](https://www.secureworld.io/industry-news/free-ransomware-removal-tool).

And it's why we are letting you know about a new Security Primer on LockerGoga ransomware, published by the Multi-State ISAC.

LockerGoga ransomware, as you may know, has been causing industrial-sized heartburn on multiple continents this year.

This includes interrupted operations at global aluminum and energy giant [Norsk Hydro](https://www.secureworld.io/industry-news/ransomware-example-2019), French engineering consulting firm Altran, and U.S. chemical companies Hexion and MPM Holdings (Momentive).

Losses for Norsk Hydro, alone, are likely at [$40 million and rising](https://www.secureworld.io/industry-news/ransomware-impact-40-million-and-counting-for-norsk-hydro).

## **MS-ISAC update on LockerGoga ransomware**

Here are a few highlights from the security update on LockerGoga in 2Q 2019:

- The ransomware's code is digitally signed using valid certificates which could let it evade security tools and get on systems.
- The CTAs reportedly use Metasploit and Cobalt Strike to move laterally across a network. They also reportedly use the Mimikatz tool to pull passwords out of memory to compromise other accounts, including those with higher privileges.
- The malware is dropped in the %TEMP% folder with random number extensions, such as the following:
  
    - %TEMP%\svc{random}.{randomnumber}.exe
    - executed as %TEMP%\svc{random}.{random number}.exe -{random} -{random} {random}
    - Example: %TEMP%\tgytutrc{4 Random Numbers}.exe
- LockerGoga then attempts to clear the Windows event logs, creates the ransom note, and begins the encryption process.

Here is the MS-ISAC [Security Primer on LockerGoga ransomware](https://www.cisecurity.org/white-papers/security-primer-lockergoga/) for additional details on this variant. And you might also want to scan the best practices to [mitigate ransomware risks.](https://www.cisecurity.org/white-papers/ms-isac-security-primer-ransomware/)

*And if you're interested in joining the InfoSec discussion on both persistent and emerging threats, check out [your region's](https://www.secureworld.io/events) SecureWorld conference in 2019.*

[View full post](https://www.secureworld.io/industry-news/ransomware-behavior-locker-goga)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "SecureWorld News Team"
  },
  "dateModified" : "2019-04-02T16:35:48.149Z",
  "datePublished" : "2019-04-02T14:13:15Z",
  "headline" : "Ransomware Resource: Security Primer on LockerGoga",
  "image" : {
    "@type" : "ImageObject",
    "height" : 839,
    "url" : "https://info.secureworldexpo.com/hubfs/ransomware-2320793_1280.jpg",
    "width" : 1280
  },
  "mainEntityOfPage" : "https://www.secureworld.io/industry-news/ransomware-behavior-locker-goga",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://cdn2.hubspot.net/hubfs/2221756/Logos/SWE/SWE_logo_full-long_forWHITEbackgrounds.jpg",
      "width" : 304.46954
    },
    "name" : "SecureWorld News"
  }
}
```