Similar to other ransomware-as-a-service (RaaS) operations, LockBit 2.0 has begun recruiting affiliates to carry out intrusions and exfiltration on targeted systems.
In the aftermath of DarkSide and REvil shutting down their operations, the LockBit gang has embarked on a hiring spree, enticing insiders to aid in compromising systems by plastering wallpapers on compromised systems and offering multimillion-dollar payouts.
LockBit 2.0 exhibits characteristics and behaviors reminiscent of Ryuk and Egregor, showcasing the influence of these notorious ransomware strains.
Recently, Bangkok Airways fell victim to a cyberattack orchestrated by the LockBit ransomware group, resulting in the exposure of stolen data. LockBit typically targets enterprises and government entities, exploiting their vulnerabilities to coerce them into paying ransoms to restore normalcy.
Accenture, a prominent outsourcing and accounting firm, also faced a LockBit attack earlier this month. With revenues of $44.33 billion in 2020 and a global workforce of 569,000 employees spanning 50 countries, Accenture allegedly received a $50 million cryptocurrency ransom demand from the cybercriminals. The deadline was repeatedly extended until Accenture concluded that the stolen data held little significance.
In yet another high-profile incident, UK train operator Merseyrail fell victim to LockBit in April 2021. Despite the trains running on schedule, the cybercriminals managed to compromise a company director's Office 365 account, exploiting it to boast about their achievement by sending emails to employees and journalists.
File Hashes:
URLs:
Tactics, Techniques, and Procedures (TTPs):
On August 23, 2021, a Russian-speaking tech blog YouTube channel called "Russian OSINT" published an interview with representatives of LockBit, unveiling crucial details about their operations. The LockBit 2.0 representative boasted about their ransomware's advanced technical features, enabling it to outperform competitors. Notable features include:
It is worth noting that LockBit refrains from targeting healthcare and educational institutions, social services, and charities, as they prioritize the development and safety of human beings.
Considering LockBit 2.0's capabilities, ongoing developments, and recruitment efforts, organizations must proactively prepare for future upgrades and heightened threats. Here are some recommendations to help prevent and mitigate the impact of LockBit attacks:
By adhering to these recommendations and best practices, organizations can fortify their defenses, mitigate the risk of LockBit attacks, and maintain robust data security and regulatory compliance. UltraViolet Cyber stands ready to support organizations in their security endeavors and safeguard their valuable assets.