Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

GoodLock Ransomware Decryption & Data Recovery

  • Active
  • Medium
  • No public decryptor

GoodLock is a low-volume Windows encryptor, captured by Antiy in September 2025 and listed by 360 as a newly seen family in June 2026. It appends .goodLock and drops ___RECOVER__FILES__.goodLock.txt. A traditional encrypt-only family with no leak site, very little public record, and no free decryptor.

First seen
2025-09
File extensions
.goodLock
Ransom notes
___RECOVER__FILES__.goodLock.txt
Affected platforms
Windows

Family profile

File extensions
  • .goodLock
Ransom notes
  • ___RECOVER__FILES__.goodLock.txt
Contact patterns
  • No contact channel is documented publicly - no verifiable mailbox domain, Tox, Telegram or onion portal
  • No leak site observed; the family does not appear in mainstream ransomware group trackers
Aliases / versions
Goodlock、GoodLock Ransomware、Trojan/MSIL.Goodlock[Ransom]
First seen
2025-09
Status
Active
Operational status
Newly emerged
Threat level
Medium
Affected platforms
  • Windows
Tags
  • Prevalent in China
  • Emerging
Decryptor
No public decryptor

There is no free public decryptor for GoodLock. The family does not appear in the No More Ransom tool list, and no vendor or law-enforcement agency has published a decryptor for it. Antiy's engine update notice of 13 September 2025 states plainly that no tool was then known to decrypt GoodLock-encrypted data, and no public research in the year since has overturned that.

It should also be said that no complete public reverse-engineering of GoodLock's ciphers or key handling exists. That means the family cannot be shown to be decryptable, nor flatly declared permanently undecryptable - the call has to come from real on-site samples. Treat any page or tool advertising "GoodLock decryption support" with heavy scepticism; such claims are usually lead generation for recovery services, or brokers who simply pay the ransom for you.

The workable order is: profile the encryption and the extent of damage from the actual encrypted files first, then choose between backups and snapshots, shadow copies, intact regions that may survive inside large files, unencrypted copies and log replay. We do not pay ransoms and do not negotiate on a client's behalf.

Sources

Latest activity

  1. 360's June 2026 ransomware report lists GoodLock as a newly observed traditional (encrypt-only, no leak site) family. Top families that month: Weaxor 32.47%, Sorry 17.75%, Wmansvcs 14.29%; Windows 10 and Server 2008 most hit.

    Sources

Overview

GoodLock is a Windows ransomware family that Chinese security vendors track but that carries very little public technical documentation. Only two points on its timeline are verifiable: Antiy Labs captured samples in September 2025 and published its extension and ransom-note signatures in the AVL SDK engine update notice of 13 September 2025 under the detection name Trojan/MSIL.Goodlock[Ransom]; 360 then listed GoodLock as a newly observed traditional ransomware family in its June 2026 monthly ransomware report.

That "traditional" label carries information. 360 splits newly seen families into double-extortion operations and traditional ones, and places GoodLock in the latter group - encryption for ransom, without an accompanying leak site. A separate check agrees: GoodLock does not appear in the group directories maintained by mainstream ransomware trackers. Unlike LockBit or Qilin, which name victims publicly, GoodLock's leverage rests almost entirely on data being unavailable.

The detection name Trojan/MSIL.Goodlock indicates a .NET (MSIL) binary. Encryptors of that kind are cheap to build and quick to iterate. For scale: in the same monthly report the top three families by infection share were Weaxor (32.47%), Sorry (17.75%) and Wmansvcs (14.29%), with Windows 10, Windows Server 2008 and Windows 7 the most-hit systems. GoodLock is nowhere near that volume.

A note on its current activity level. We checked 360's two following monthly reports - July 2026 (published 13 August 2026) and August 2026 (published 8 September 2026) - and GoodLock appears in neither, not among the newly added families and not in the infection-share tables. Read that carefully: 360 names only new families and those clearing a reporting threshold, so absence is not proof the family has stopped. It does mean no new publicly visible record has accumulated since June 2026. This page therefore marks the lifecycle as emerging rather than established: a single month on a tracker is too thin to support a claim of sustained circulation.

To be candid: public information on GoodLock is limited. Its initial access route, ciphers, whether it deletes shadow copies, whether any Linux or ESXi encryptor exists, and the contact and payment channels inside the note are all unconfirmed, and this page does not fill those gaps with guesswork.

How to identify it

Extension. .goodLock is appended to the full original filename, with the mixed casing (capital L) preserved - config.ini becomes config.ini.goodLock. The suffix is fixed rather than randomised, so searching by it is a reliable first-pass check.

Ransom note. ___RECOVER__FILES__.goodLock.txt is dropped on the desktop. As printed in the Antiy notice the underscore runs are three, then two, then two. Do not treat the underscore count as a hard test: advisories and pages that republish the name routinely swallow or merge runs of underscores, and we read inconsistent spellings across sources while checking this. Match on the three-part pattern RECOVER / FILES / .goodLock.txt and then go by the filename actually on disk. The name remains the most dependable attribution signal; no other family in public reporting uses it.

Targeted file types - an important difference. Antiy describes the analysed sample as traversing system directories and encrypting files with the ini, exe and lnk extensions. That departs sharply from the usual pattern of hitting documents, databases and archives first. Where the site matches that description, the symptom set is "documents appear intact, but programs will not launch, every shortcut is broken and services fail to start" rather than the more familiar wall of renamed data files.

How to attribute, and what to watch for.

  • Lead with the note filename and corroborate with the extension; both present together is effectively conclusive.
  • Antiy's description comes from a specific sample and is not a complete encryption manifest for every variant. Inventory what was actually encrypted on site rather than assuming.
  • Do not attribute on contact details - no mailbox domain, Tox ID or onion portal has been publicly recorded for this family.
  • Because the binary is .NET, managed-code processes and .NET runtime loading artefacts are usually visible on the host and can support memory forensics.

Infection vectors

No public report describes how GoodLock gains initial access or moves laterally, and we will not guess. The Antiy notice offers only generic hardening advice - strong passwords, prompt patching, closing high-risk ports such as 3389/445/139/135, caution with suspicious mail attachments and links, restricting PowerShell, and offline backups. That is a baseline for ransomware in general and cannot be read backwards as a confirmed kill chain for this family.

What can inform triage is the wider domestic picture from the same period. 360's June 2026 report shows the month's leading families spreading through vulnerabilities in software common at smaller companies, component authentication flaws and fileless techniques, plus remote desktop logins; servers and desktop PCs were hit in roughly equal measure, with legacy builds such as Windows Server 2008 and Windows 7 heavily represented. For Chinese organisations these remain the priority self-checks:

  • Internet-exposed remote desktop and administration entry points, especially accounts with weak passwords or no multi-factor authentication.
  • Long-unpatched legacy Windows servers and end-of-support middleware.
  • Mail attachments and download sources disguised as common software or cracking tools.
  • Backup storage directly reachable from the LAN, and backup systems sharing credentials with production.

For any individual GoodLock incident, the entry point has to come from on-site forensics - logs, account activity and dropped files - not from assumptions borrowed elsewhere.

Encryption behavior

No complete public reverse-engineering of the GoodLock encryptor exists, so the following separates what is evidenced from what is not.

Evidenced (from Antiy's description of the captured sample):

  • It traverses operating-system directories before encrypting.
  • It encrypts files with the ini, exe and lnk extensions and appends .goodLock.
  • It drops ___RECOVER__FILES__.goodLock.txt on the desktop.
  • No effective decryption tool existed as of the notice.

Not evidenced: the specific symmetric and asymmetric cipher combination, key generation and wrapping, whether intermittent or block-based encryption is used, whether shadow copies are deleted and logs cleared, whether database and backup processes are terminated, how network shares and mapped drives are handled, and whether any Linux, ESXi or NAS encryptor exists.

That distinction shapes the recovery plan, and the target list matters most. If only ini, exe and lnk files were in fact encrypted on site, the business data itself may be intact and the work shifts toward restoring system and application availability rather than rescuing data. If the actual scope is wider - variants can and do broaden their target types - then the standard approach applies: measure which regions of large files were overwritten and determine whether databases and virtual disks still offer structural repair space. That measurement requires the real encrypted files; it cannot be inferred from the family name.

Assess before you act

Recoverability assessment

Whether GoodLock-encrypted systems can be recovered has to be judged site by site. We do not pay ransoms and do not negotiate; our work is technical recovery and forensics.

1) Free decryptor: none. No More Ransom, security vendors and law enforcement have published nothing for GoodLock, and no exploitable key-handling flaw has been disclosed. Treat pages claiming direct decryption with scepticism.

2) Establish the real encryption scope first - specific to this family. Public reporting describes GoodLock targeting ini, exe and lnk files, so the opening move is an inventory rather than a rescue: which artefacts are configuration and program files, and which are actual business data. If the data itself was untouched, recovery is mostly reinstalling applications, restoring configuration, and rebuilding shortcuts and service registrations - far cheaper and faster than a typical ransomware event. If the scope on site is broader, work down the tiers below.

3) Profile the encryption pattern (results depend on it). Take three to five encrypted files of different sizes and map which regions were overwritten and at what stride. If block-based or intermittent encryption is confirmed, database files (MDF/LDF, DBF, ibd), virtual disks (vmdk/vhdx) and mail stores may retain large intact areas that page-level extraction and structural rebuilds can exploit. If whole files were encrypted, this route is closed.

4) Backups, snapshots and shadow copies. Offline and offsite backups, storage-layer snapshots on NAS/SAN, hypervisor snapshots, untouched copies on the backup server, and cloud version history. Because it is not publicly confirmed whether this family deletes shadow copies, check them early rather than assuming they are gone. Confirm the network is clean of any foothold before restoring.

5) Unencrypted copies and log replay. File-server recycle bins, endpoint caches, reporting and BI staging databases, ERP archive exports, database transaction logs and application audit logs can support reconstruction or point-in-time replay.

6) Low-level carving. If the encryptor writes a new file and deletes the original, source data may survive in unallocated clusters and can be recovered by raw sector scanning. This requires stopping all writes to the affected volumes immediately.

We commit to a verifiable assessment and a clearly bounded recovery scope. We never claim "100% decryption", and no technique guarantees full recovery.

Our response plan

Hit by GoodLock ransomware? What to do

  1. Containment and forensic preservation

    Disconnect affected hosts from production networks and storage paths while preserving memory and disk state. Do not reboot or power off - GoodLock is a .NET encryptor, and managed objects and key material in memory are a significant forensic source that disappears with the power. Image or snapshot domain controllers, file servers and the backup server first, export logs from edge devices, remote desktop gateways and Active Directory, and keep three to five .goodLock files plus the original ___RECOVER__FILES__.goodLock.txt from the desktop.

  2. Family identification and encryption-scope inventory

    Confirm the family by cross-checking the note filename against the .goodLock extension, ruling out copycats and repackaged samples reusing the suffix. Then inventory every file type and path that was actually encrypted - a step that matters unusually much here: public reporting points at ini, exe and lnk, but the site may differ, and the loss surface must be defined by measurement rather than by the published description. In parallel, analyse the sample in an isolated environment and map file header and trailer structures and which regions were overwritten.

  3. Recoverability assessment and plan sign-off

    Assess system by system: whether shadow copies survive, whether backups and storage snapshots are usable and uncontaminated, whether critical databases and VMs offer structural repair space, and which applications and configurations can be restored quickly from images and baselines. Deliver a written assessment stating which systems go the backup-rollback route, which need structural repair and which merely need their runtime environment rebuilt, with expected recovery scope, timelines and a business restoration order. Execute only after sign-off.

  4. Recovery execution and business verification

    All work happens on images or copies, with originals kept read-only. Restore in business priority order: identity and domain controllers first, then core databases and line-of-business systems, then file services, endpoints and the office environment. Because this family damages executables and shortcuts, verify service registrations, scheduled tasks, application configuration files and licence files alongside the data, so you do not end up with files restored but systems that will not start. After each batch, run integrity checks and business-side verification - reconciliation, report comparison, application start-up tests - and record everything in a traceable recovery manifest.

  5. Attribution, hardening and handover

    Reconstruct the kill chain: whether entry came through exposed remote desktop, a weak-password account, an unpatched legacy server or a poisoned download; how long the actors dwelled; and the privilege-escalation and deployment paths used. Remove persistence, rogue accounts and scheduled tasks, reset credentials domain-wide and enforce MFA on remote access, close unnecessary high-risk ports, upgrade or segment end-of-support Windows builds, rebuild backups to a 3-2-1 design with immutable copies, and close with an incident report and a formal handover checklist.

Risk warning

What not to do

  • Do not reboot or power off affected hosts. GoodLock is a .NET encryptor, and losing memory-resident managed objects, processes and connections destroys both forensic evidence and possible recovery leads - isolate the network instead of cutting power.
  • Do not delete the ___RECOVER__FILES__.goodLock.txt note from the desktop or the encrypted samples, and do not rename or move .goodLock files. They are the only basis for identifying the family and profiling the encryption.
  • Do not download and run anything advertised as a "GoodLock decryptor". No free decryptor exists for this family; such programs are at best useless and at worst destructive, and any trial belongs on copies.
  • Do not put systems straight back into production just because documents look intact - this family may have damaged executables and configuration files, and running on regardless overwrites forensic traces and can re-trigger a residual encryptor.
  • Do not format, reinstall or rebuild RAID sets and storage pools, and do not rush to install software onto the original disks; overwriting them permanently removes the carving option.
  • Do not attach backup media or restore the backup server before the network is confirmed clean, or the backups may be encrypted or destroyed in turn.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

GoodLock Frequently asked questions

  • Can .goodLock files be decrypted?

    There is no free public decryptor. GoodLock does not appear in the No More Ransom tool list, and Antiy's September 2025 notice stated that no effective decryption tool was known; nothing has been published in the year since. Whether recovery remains possible depends on the actual encryption scope on site, how intact shadow copies and backups are, and whether large files retain repairable regions - all assessed against real samples, never inferred from the extension. Any promise of guaranteed recovery should be distrusted.

  • ___RECOVER__FILES__.goodLock.txt appeared on my desktop - which ransomware is this?

    That is the ransom-note filename currently associated with the GoodLock family; Antiy published the signature in an engine update notice, and together with the .goodLock extension it effectively pins down attribution. Two caveats: note filenames can be reused by other crews, so hand the note plus three to five encrypted files to an analyst for cross-confirmation; and no contact or payment channel has been publicly recorded for this family, so the contact details in a note cannot be used to attribute it.

  • Only executables and shortcuts were encrypted and documents look fine - is this serious?

    Public reporting describes this family hitting ini, exe and lnk files. The immediate effect is that programs will not launch, services fail to start and the system is half-paralysed, while the business data itself may be untouched - where that holds, recovery costs far less than a typical ransomware event. But do not relax on that basis. First, the real encryption list must be confirmed by on-site inventory; variants can broaden their targets. Second, an encryptor writing into system directories means the attacker already held elevated privileges, so the entry point and any persistence must be found. Third, do not restore services on a compromised host - isolate and investigate first, then rebuild the runtime environment according to the assessment.

  • Does GoodLock steal data and publish victims on a leak site?

    There is no evidence that it does. 360's June 2026 report classifies GoodLock as a traditional ransomware family, listed separately from that month's double-extortion crews, and it does not appear in the group directories of mainstream ransomware trackers, indicating no leak site. That does not mean exfiltration checks can be skipped: whether data left the network depends on the specific intrusion rather than the family label, so review egress traffic, signs of bulk outbound transfers and access auditing on sensitive directories, and let that drive notification duties and the scope of credential rotation.

  • Why is there so little information on GoodLock, and does that affect response?

    Because it is small, has no leak site, and no mainstream vendor has published a full sample analysis - the verifiable public record consists of Antiy's September 2025 engine notice and 360's June 2026 monthly report, with no further mention in 360's July or August 2026 reports. English-language searches are further drowned out by Samsung's unrelated Good Lock customisation suite. Thin documentation limits what can be predicted in advance, but it does not limit response: a recovery plan should rest on on-site measurement anyway - inventorying the encryption scope, profiling the encryption pattern, verifying backups and snapshots. Those conclusions come from your environment, not from a published report. We run 24/7 emergency response and can provide an initial family assessment and recovery path after remote access.