NailaoLocker Ransomware's 'Cheese'
Fortinet, Friday, July 18th, 2025
Built-In Decryption or Just Another Trap?
FortiGuard Labs recently ran across NailaoLocker, a ransomware variant targeting Microsoft Windows systems. Like many ransomware families, it uses AES-256-CBC to encrypt user files. What sets it apart is the presence of hard-coded SM2 cryptographic keys and a built-in decryption function-an uncommon combination that raises immediate questions about intent.