BreachCensus

xinglocker

First seen April 29, 2021Active21 claimed victims

The claims below are reproduced as posted by xinglocker on its own leak site. Such claims are frequently wrong or exaggerated, and are unverified. Organisations listed here have not been confirmed to have suffered a breach.

Listed organisation? Contact [email protected].

Profile

XingLocker is a ransomware group that emerged in May 2021 as part of a franchise-style RaaS model built on a customized MountLocker payload, using IcedID for initial access and Windows Active Directory APIs for worm-style lateral movement across networks.

Description from ransomware.live.

Claimed victims (as posted by the group — unverified)

Victim (as posted)Claimed onSourcePress coverage
Wayne Automatic Fire Sprinklers, Inc.October 26, 2021ransomware_live
Tilia GmbH. TILIA GROUPOctober 8, 2021ransomware_live
J.Irwin CompanyAugust 17, 2021ransomware_live
DiaSorinJuly 8, 2021ransomware_live
Greenwood Fabricating & PlatingJune 3, 2021ransomware_live
AQUALUNGJune 2, 2021ransomware_live
Positive Promotions, Inc.June 2, 2021ransomware_live
Sharafi Group InvestmentsMay 27, 2021ransomware_live
T.I.S. GroupMay 24, 2021ransomware_live
Coastal Family Health CenterMay 24, 2021ransomware_live
OSF Healthcare SystemMay 18, 2021ransomware_live
LineStarMay 14, 2021ransomware_live
Solen A.SMay 14, 2021ransomware_live
CBN LogisticMay 14, 2021ransomware_live
Desert Plastering LLCMay 13, 2021ransomware_live
Gulfeagle SupplyMay 11, 2021ransomware_live
GlobeMed SaudiMay 6, 2021ransomware_live
Washoe TribeMay 6, 2021ransomware_live
Bridgelux, Inc.May 6, 2021ransomware_live
NAVNIT GROUPApril 29, 2021ransomware_live
Pezzuto GroupApril 29, 2021ransomware_live

Claim data from ransomware.live and RansomLook (CC BY 4.0).