Quantum Ransomware Makes the Leap in Just Four Hours

Share This Post

A new ransomware known as Quantum Locker has been observed in the wild recently. This ransomware is a rebranded version of the MountLocker ransomware campaign that first launched in September of 2020. The DFIR Report recently detailed a case involving this variant. In under four hours, threat actors went from initial access to a domain-wide encryption event.

The initial access vector was an IcedID payload believed to have been delivered via an email. IcedID is a modular banking trojan that consists of DLL files which can be loaded into memory by rundll32.exe. This initial payload has been commonly used by other ransomware gangs, such as REvil, XingLocker and Conti.

Once in, the attacker(s) ran a batch file that executed “nslookup” against every host in the environment. They proceeded to access LSASS memory and extract credentials, which were later used to execute WMI discovery tasks on servers within the victim environment.

In the next hour, the threat actor made remote desktop connections to other servers and copied the ransomware to the admin share (c$) on each host discovered. The payloads were then executed using a combination of three methods: scheduled task, WMI, or PsExec.

The speed and sophistication of this attack suggests it isn’t the first time we will see it. For a detailed analysis and breakdown of the attack, visit: https://thedfirreport.com/2022/04/25/quantum-ransomware/.



Reach out to our incident response team for help

More To Explore

Information Security News – 4/14/2025

Oracle Confirms “Obsolete Servers” Hacked Article link: https://www.bleepingcomputer.com/news/security/oracle-says-obsolete-servers-hacked-denies-cloud-breach/    Phishing Kits Now Vet Victims in Real-Time Before Stealing Credentials Article link: https://www.bleepingcomputer.com/news/security/phishing-kits-now-vet-victims-in-real-time-before-stealing-credentials/    Neptune RAT

Information Security News – 4/7/2025

Criminal Group Claims Responsibility for Cyberattack on Minnesota Casino Article Link: https://cdcgaming.com/brief/cybersecurity-incident-at-minnesota-tribal-community-casino-prompts-shutdown/ As CISA Downsizes, Where Can Enterprises Get Support? Article Link: https://www.darkreading.com/cybersecurity-operations/roundtable-cisa-downsizes-where-can-enterprises-look-support Oracle Privately

Do You Want to Shore Up Your Defenses?

We're opening our first round of threat hunting engagements to 100 organizations. Sign up or join the wait list here.