top of page
Mitre
Alias
Lockbit Gang
Country
[unknown]
Sponsor
Nil
Motivation
Financial Gain
First Seen
2019
Description
(Bleeping Computer) LockBit ransomware takes as little as five minutes to deploy the encryption routine on target systems once it lands on the victim network.
Joining the ransomware-as-a-service (RaaS) business in September 2019, LockBit is atypical in that it�s driven by automated processes for quick spreading across the victim network, identifying valuable systems and locking them up.
LockBit attacks leave few traces for forensic analysis as the malware loads into the system memory, with logs and supporting files removed upon execution.
Targeted
Industries
Aviation, Defense, Energy, Financial, Healthcare, Transportation
Targeted
Countries
Worlwide
Tools
Crackmapexec
Empireproject
Lockbit
Mimikatz
Psexec
TTP
Nil
Operations
Performed
[2020-05] lockbit Ransomware Self-spreads To Quickly Encrypt 225 Systems (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-self-spreads-to-quickly-encrypt-225-systems/)
[2020-08] interpol: Lockbit Ransomware Attacks Affecting American Smbs (https://www.bleepingcomputer.com/news/security/interpol-lockbit-ransomware-attacks-affecting-american-smbs/)
[2020-09] lockbit Ransomware Launches Data Leak Site To Double-extort Victims (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-launches-data-leak-site-to-double-extort-victims/)
[2020-12] ransomware Hits Helicopter Maker Kopter (https://www.zdnet.com/article/ransomware-hits-helicopter-maker-kopter/)
[2021-04] uk Rail Network Merseyrail Likely Hit By Lockbit Ransomware (https://www.bleepingcomputer.com/news/security/uk-rail-network-merseyrail-likely-hit-by-lockbit-ransomware/)
[2021-06] lockbit Resurfaces With Version 2.0 Ransomware Detections In Chile, Italy, Taiwan, Uk (https://www.trendmicro.com/en_us/research/21/h/lockbit-resurfaces-with-version-2-0-ransomware-detections-in-chi.html)
[2021-08] energy Group Erg Reports Minor Disruptions After Ransomware Attack (https://www.bleepingcomputer.com/news/security/energy-group-erg-reports-minor-disruptions-after-ransomware-attack/)
[2021-08] lockbit Ransomware Recruiting Insiders To Breach Corporate Networks (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-recruiting-insiders-to-breach-corporate-networks/)
[2021-08] lockbit 2.0 Ransomware Incidents In Australia (https://www.cyber.gov.au/acsc/view-all-content/alerts/lockbit-20-ransomware-incidents-australia)
[2021-08] accenture Confirms Hack After Lockbit Ransomware Data Leak Threats (https://www.bleepingcomputer.com/news/security/accenture-confirms-hack-after-lockbit-ransomware-data-leak-threats/)
[2021-08] lockbit Ransomware Wants To Hire Your Employees (https://www.cybereason.com/blog/lockbit-ransomware-wants-to-hire-your-employees)
[2021-08] bangkok Air Confirms Passenger Pii Leak After Ransomware Attack (https://therecord.media/bangkok-air-confirms-passenger-pii-leak-after-ransomware-attack/)
[2021-09] lockbit 2.0: Ransomware Attacks Surge After Successful Affiliate Recruitment (https://securityintelligence.com/posts/lockbit-ransomware-attacks-surge-affiliate-recruitment/)
[2021-10] lockbit 2.0 Ransomware Hit Israeli Defense Firm E.m.i.t. Aviation Consulting (https://securityaffairs.co/wordpress/122892/cyber-crime/e-m-i-t-aviation-consulting-ransomware.html)
[2021-11] blackmatter Ransomware Moves Victims To Lockbit After Shutdown (https://www.bleepingcomputer.com/news/security/blackmatter-ransomware-moves-victims-to-lockbit-after-shutdown/)
[2022-01] infamous Ransomware Group Claims It Hacked France�s Justice Ministry (https://www.politico.eu/article/infamous-ransomware-group-claims-it-hacked-frances-justice-ministry/)
[2022-01] lockbit Ransomware Gang Claims Paybito Crypto Exchange As New Victim (https://www.hackread.com/lockbit-ransomware-paybito-crypto-exchange-hack/)
[2022-02] bridgestone Americas Confirms Ransomware Attack, Lockbit Leaks Data (https://www.bleepingcomputer.com/news/security/bridgestone-americas-confirms-ransomware-attack-lockbit-leaks-data/)
[2022-03] rail Giant Wabtec Discloses Data Breach After Lockbit Ransomware Attack (https://www.bleepingcomputer.com/news/security/rail-giant-wabtec-discloses-data-breach-after-lockbit-ransomware-attack/)
[2022-04] rio De Janeiro Finance Department Hit With Lockbit Ransomware (https://therecord.media/rio-de-janeiro-finance-department-hit-with-lockbit-ransomware/)
[2022-04] lockbit, Hive, And Blackcat Attack Automotive Supplier In Triple Ransomware Attack (https://news.sophos.com/en-us/2022/08/10/lockbit-hive-and-blackcat-attack-automotive-supplier-in-triple-ransomware-attack/)
[2022-05] lockbit 2.0 Posted A Notice To The Dark Web Portal It Uses To Identify And Extort Its Victims Saying It Had Files From The Bulgarian State Agency For Refugees Under The Council Of Ministers. (https://www.cyberscoop.com/lockbit-ransomware-attack-bulgarian-refugee-agency/)
[2022-05] canadian Fighter Jet Training Company Investigating Ransomware Attack (https://therecord.media/top-aces-ransomware-attack-lockbit/)
[2022-05] foxconn Confirms Ransomware Attack Disrupted Production In Mexico (https://www.bleepingcomputer.com/news/security/foxconn-confirms-ransomware-attack-disrupted-production-in-mexico/)
[2022-06] mandiant: �no Evidence� We Were Hacked By Lockbit Ransomware (https://www.bleepingcomputer.com/news/security/mandiant-no-evidence-we-were-hacked-by-lockbit-ransomware/)
[2022-06] lockbit Ransomware Disguised As Copyright Claim E-mail Being Distributed (https://asec.ahnlab.com/en/35822/)
[2022-06] lockbit Claims Ransomware Attack On Security Giant Entrust, Leaks Data (https://www.bleepingcomputer.com/news/security/lockbit-claims-ransomware-attack-on-security-giant-entrust-leaks-data/)
[2022-06] lockbit 3.0 Introduces The First Ransomware Bug Bounty Program (https://www.bleepingcomputer.com/news/security/lockbit-30-introduces-the-first-ransomware-bug-bounty-program/)
[2022-07] french Telecom Company La Poste Mobile Struggling To Recover From Ransomware Attack (https://therecord.media/french-telecom-company-la-poste-mobile-struggling-to-recover-from-ransomware-attack/)
[2022-07] ransomware Gang Now Lets You Search Their Stolen Data (https://www.bleepingcomputer.com/news/security/ransomware-gang-now-lets-you-search-their-stolen-data/)
[2022-07] lockbit Claims Ransomware Attack On Italian Tax Agency (https://www.bleepingcomputer.com/news/security/lockbit-claims-ransomware-attack-on-italian-tax-agency/)
[2022-07] the Prolific Lockbit Ransomware Gang Appears To Have Claimed Another Two Scalps In Recent Days: The Canadian Town Of St Marys And The Italian Tax Agency. (https://www.infosecurity-magazine.com/news/lockbit-ramps-up-attacks-on-public/)
[2022-08] lockbit Ransomware Gang Gets Aggressive With Triple-extortion Tactic (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-gets-aggressive-with-triple-extortion-tactic/)
[2022-09] lockbit Updates Leak Site With Post About Sud-francilien Hospital (https://www.databreaches.net/lockbit-updates-leak-site-with-post-about-sud-francilien-hospital/)
[2022-09] virginia County Confirms Personal Information Stolen In Ransomware Attack (https://www.securityweek.com/virginia-county-confirms-personal-information-stolen-ransomware-attack)
[2022-10] microsoft Exchange Servers Hacked To Deploy Lockbit Ransomware (https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-lockbit-ransomware/)
[2022-10] japanese Tech Firm Oomiya Hit By Lockbit 3.0. Multiple Supply Chains Potentially Impacted (https://securityaffairs.co/wordpress/137243/cyber-crime/oomiya-lockbit-3-0-ransomware.html)
[2022-10] pendragon Car Dealer Refuses $60 Million Lockbit Ransomware Demand (https://www.bleepingcomputer.com/news/security/pendragon-car-dealer-refuses-60-million-lockbit-ransomware-demand/)
[2022-11] lockbit Ransomware Claims Attack On Continental Automotive Giant (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-claims-attack-on-continental-automotive-giant/)
[2022-11] lockbit 3.0 Gang Claims To Have Stolen Data From Kearney & Company (https://securityaffairs.co/wordpress/138136/cyber-crime/lockbit-ransomware-kearney-company.html)
[2022-11] "lockbit 3.0 Says Its Holding A Canadian City For Ransom (https://www.bankinfosecurity.com/lockbit-30-says-its-holding-canadian-city-for-ransom-a-20529")
[2022-11] lockbit Takes Credit For November Ransomware Attack On Sacramento Pbs Station (https://therecord.media/lockbit-takes-credit-kvie-pbs-ransomware/)
[2022-12] "lockbit Claims Attack On Californias Department Of Finance (https://www.bleepingcomputer.com/news/security/lockbit-claims-attack-on-californias-department-of-finance/")
[2022-12] lockbit Ransomware Used In Attack On Ohio Town�s Court, Police Department And More (https://therecord.media/lockbit-ransomware-group-attacks-ohio-towns-court-police-department-and-more/)
[2022-12] port Of Lisbon Website Still Down As Lockbit Gang Claims Cyberattack (https://therecord.media/port-of-lisbon-website-still-down-as-lockbit-gang-claims-cyberattack/)
[2022-12] lockbit 3.0 Gives Sick Kids Free Decryptor, Claims To Ban Partner Who Attacked Them (https://www.databreaches.net/breaking-lockbit-3-0-gives-sick-kids-free-decryptor-claims-to-ban-partner-who-attacked-them/)
[2022-12] los Angeles� Housing Authority Hit By Lockbit (https://www.databreaches.net/los-angeles-housing-authority-hit-by-lockbit-claim/)
[2023-01] lockbit Ransomware Gang Claims Royal Mail Cyberattack (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-claims-royal-mail-cyberattack/)
[2023-01] "lockbit Ransomware Goes green, Uses New Conti-based Encryptor (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-goes-green-uses-new-conti-based-encryptor/")
[2023-02] lockbit Gang Takes Credit For Attack On Water Utility In Portugal (https://therecord.media/porto-portugal-water-utility-cyberattack-lockbit)
[2023-02] washington State Public Bus System Confirms Ransomware Attack (https://therecord.media/pierce-transit-washington-ransomware-attack-lockbit)
[2023-02] lockbit Ransomware Gang Now Also Claims City Of Oakland Breach (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-now-also-claims-city-of-oakland-breach/)
[2023-03] "lockbit Brags: Well Leak Thousands Of Spacex Blueprints Stolen From Supplier (https://www.theregister.com/2023/03/13/lockbit_spacex_ransomware/")
[2023-03] lockbit Ransomware Claims Essendant Attack, Company Says �network Outage� (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-claims-essendant-attack-company-says-network-outage-/)
[2023-03] data Stolen From Florida Sheriff�s Office Leaked By Lockbit Ransomware Group (https://therecord.media/florida-sheriff-data-leak-lockbit-ransomware)
[2023-03] lockbit Leaks Data Stolen From The South Korean National Tax Service (https://securityaffairs.com/144342/cyber-crime/lockbit-south-korean-national-tax-service.html)
[2023-04] darktrace: Investigation Found No Evidence Of Lockbit Breach (https://www.bleepingcomputer.com/news/security/darktrace-investigation-found-no-evidence-of-lockbit-breach/)
[2023-04] lockbit Ransomware Encryptors Found Targeting Mac Devices (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-encryptors-found-targeting-mac-devices/
Counter
Operations
'date': '2022-08', 'activity': 'lockbit Ransomware Blames Entrust For Ddos Attacks On Leak Sites (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-blames-entrust-for-ddos-attacks-on-leak-sites/', 'date': '2022-09', 'activity': 'lockbit Ransomware Builder Leaked Online By �angry Developer� (https://www.bleepingcomputer.com/news/security/lockbit-ransomware-builder-leaked-online-by-angry-developer-/', 'date': '2022-11', 'activity': 'man Charged For Participation In Lockbit Global Ransomware Campaign (https://www.justice.gov/opa/pr/man-charged-participation-lockbit-global-ransomware-campaign'
Information
https://www.bleepingcomputer.com/news/security/lockbit-ransomware-moves-quietly-on-the-network-strikes-fast/
https://s3.amazonaws.com/talos-intelligence-site/production/document_files/files/000/095/481/original/010421_LockBit_Interview.pdf
https://therecord.media/ransomware-diaries-undercover-with-the-leader-of-lockbit/
https://securityintelligence.com/articles/how-lockbit-changed-cybersecurity/
bottom of page