MountLocker ransomware encrypts company and business user data with ChaCha20 + RSA-2048. It then demands a $ 2 million ransom in BTC to get the files back.It gives the hacked company 3 days and threatens to publish the stolen data "all over the Internet" in order to increase pressure on the victim. To do this, ransomware operators start stealing data even before encrypting files.
A new version of MountLocker is released which is targeting TurboTax files. It explicitly look for files having the .tax, .tax2009, .tax2013, .tax2014
MountLocker Ransomware Signatures
MountLocker Ransomware Download