LockBit Ransomware Returns With More Effective Attacks

Share post:

Cybersecurity researchers at Trend Micro have been recording an increase in LockBit ransomware campaigns since July. This ransomware-as-a-service first appeared in September 2019 and was quite successful.

LockBit authors claim that LockBit 2.0 is one of today’s fastest file-encrypting ransomware variants in ads in underground forums. Those claims have proven interesting to cybercriminals seeking to make money from ransomware.

Trend Micro researchers have observed several LockBit ransomware campaigns in recent weeks, mainly targeting organizations in Chile, the U.K., Italy and Taiwan.

While LockBit remained under the radar for much of this year, it launched a major attack against Accenture’s professional services company.

LockBit also appears to have benefited from the apparent disappearance of ransomware gangs including REvil and Darkside, with affiliates of those groups turning towards LockBit as their pathway to launch fresh ransomware attacks.

Hackers often gain access to networks via compromised Remote Desktop Protocol (RDP) or VPN accounts that have been leaked or stolen. Alternatively, LockBit attacks sometimes attempt to trick insiders into accessing them with legitimate credentials.

LockBit also succeeds by copying the steps of notorious ransomware groups through certain tactics, techniques and procedures (TTPs) during attacks. LockBit, for example, now uses Ryuk’s Wake-on-LAN function and sends packets to wake offline devices to help them move sideways around networks and compromise as many machines as possible.

LockBit also uses a tool that was previously used by Egregor ransomware – printers in the network to print out ransom notes.

Like many of the most notorious ransomware groups, LockBit adds a double extortion element to the attacks by stealing the victim’s data and threatening to release it if the ransom is not paid as soon as a period expires.

For more information, read the original story in ZDNet.



Related articles

Microsoft to block emails from “Persistently Vulnerable Exchange Servers”

Microsoft has announced a new security feature for Exchange Online that will gradually throttle and eventually block emails...

Pinduoduo removed from Google Play Store after cyberattack

According to security researchers at Lookout, Pinduoduo has been involved in a complex malware attack through its application,...

Twitter source code leaked, demands GitHub reveal who posted it there

New York Times says the code posted on GitHub had been there for months. raising securit

Okta’s login flaw exposes users to attack, says Mitiga

According to Mitiga, Okta's login system contains a simple error that could expose its users to future attacks. Users...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways