{
	"id": "470568a2-a040-4973-9cd1-2b18b5398e6b",
	"created_at": "2026-04-06T00:10:17.110605Z",
	"updated_at": "2026-04-10T03:20:54.576216Z",
	"deleted_at": null,
	"sha1_hash": "bf1c8c83f13f1c514ae185488320d5d8e5434191",
	"title": "Fs0ciety Locker Ransomware Analysis",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 38604,
	"plain_text": "Fs0ciety Locker Ransomware Analysis\r\nBy Elastio\r\nPublished: 2025-07-30 · Archived: 2026-04-05 14:10:09 UTC\r\n1. Home\r\n2. Research\r\n3. Fs0ciety Locker\r\nRansomware Research\r\nFs0ciety Locker is a malicious ransomware strain that encrypts victim files and demands ransom payment for\r\ndecryption. First observed in the wild on September 1, 2016, this ransomware has been actively targeting systems\r\nworldwide.\r\nQuick facts\r\nRansomware Family\r\nFs0ciety Locker\r\nFirst Seen\r\nSeptember 1, 2016\r\nHow Fs0ciety Locker ransomware works\r\nFile encryption patterns\r\nFs0ciety Locker modifies encrypted files using specific patterns to mark them as encrypted:\r\nExtensions added after encryption\r\n.realfs0ciety@sigaint.org.fs0ciety\r\nRansom note and payment demands\r\nAfter encrypting files, Fs0ciety Locker displays ransom notes demanding payment for file recovery:\r\nfilefs0ciety.html\r\nnotes/fs0ciety.html\r\nLocation: RansomPayloadStartFolder\r\nhttps://elastio.com/detectable-ransomware/fs0ciety-locker/\r\nPage 1 of 2\n\nTechnical indicators\r\nAssociated executable files\r\nThe following executable files are associated with Fs0ciety Locker ransomware:\r\ndriver_update.exe\r\ndriver_update[1].exe\r\nInvoice_payment.docm\r\nAbout this analysis\r\nThis Fs0ciety Locker ransomware analysis is part of Elastio's comprehensive ransomware detection database.\r\nElastio provides advanced ransomware protection and recovery, helping organizations defend against and recover\r\nfrom ransomware attacks like Fs0ciety Locker.\r\nLast updated: December 30, 2025\r\nDetection coverage\r\nElastio detects Fs0ciety Locker inside your data and backups.\r\nThe Hunt Engine uses Deep File Inspection to identify Fs0ciety Locker across live data, replicated data, and\r\nbackups. If this family is in your environment, Elastio finds it before encryption completes. Run a scan against\r\nyour recovery points to confirm.\r\nRecent ransomware\r\nExplore other threats in our database\r\nSource: https://elastio.com/detectable-ransomware/fs0ciety-locker/\r\nhttps://elastio.com/detectable-ransomware/fs0ciety-locker/\r\nPage 2 of 2",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"Malpedia"
	],
	"references": [
		"https://elastio.com/detectable-ransomware/fs0ciety-locker/"
	],
	"report_names": [
		"fs0ciety-locker"
	],
	"threat_actors": [],
	"ts_created_at": 1775434217,
	"ts_updated_at": 1775791254,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/bf1c8c83f13f1c514ae185488320d5d8e5434191.pdf",
		"text": "https://archive.orkl.eu/bf1c8c83f13f1c514ae185488320d5d8e5434191.txt",
		"img": "https://archive.orkl.eu/bf1c8c83f13f1c514ae185488320d5d8e5434191.jpg"
	}
}