DMA Locker

DMA Locker targets Windows OS and one known method of distribution is through Remote Desktop. Once an infection occurs and the executable is launched, DMA Locker terminates any applications used for backing up data and adds registry keys to maintain persistence. It then whitelists all system and executable files and proceeds to encrypt all other files located on local drives, mapped network shares, and even unmapped network shares.

