Ransomware Research

Admin Locker Ransomware

Admin Locker is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption.

Quick Facts

Ransomware Family
Admin Locker

How Admin Locker Ransomware Works

File Encryption Patterns

Admin Locker modifies encrypted files using specific patterns to mark them as encrypted:

File extensions added after encryption:

..1admin..2admin..3admin..admin1..admin2..admin3

Ransom Note and Payment Demands

After encrypting files, Admin Locker displays ransom notes demanding payment for file recovery:

file!DECRYPT_FILES.txt

Ransom message:

notes/!DECRYPT_FILES.txt

Note locations:

EveryFolder
file!!!Recovery File.txt

Ransom message:

notes/!!!Recovery File.txt

Note locations:

EveryFolder

Elastio Can Help You

Don't let Admin Locker ransomware take over your data

Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.

About This Analysis

This Admin Locker ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Admin Locker.

Last updated: July 30, 2025