Inside the Cyberthreat That’s Costing Millions

lockbit-ransomware

US government agencies have released a joint cybersecurity advisory detailing indicators of compromise (IoCs) and tactics, techniques, and procedures (TTPs) related to the infamous LockBit 3.0 ransomware.

“LockBit 3.0 ransomware operates as a Ransomware-as-a-Service (RaaS) model and is a continuation of the ransomware, LockBit 2.0, and previous versions of LockBit,” officials said.

This alert is courtesy of the U.S. Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multistate Center for Information Sharing and Analysis (MS-ISAC).

Since its emergence in late 2019, LockBit actors have put significant technical effort into developing and fine-tuning the malware, with two major updates: LockBit 2.0 released in mid-2021 and released LockBit 3.0). The two versions are also known as LockBit Red and LockBit Black respectively.

According to the warning, “LockBit 3.0 accepts additional arguments for certain operations in lateral movement and rebooting in safe mode.” “If LockBit affiliates cannot access the passwordless LockBit 3.0 ransomware, password arguments will be mandatory during ransomware execution.”

The ransomware is also designed to only infect machines with language settings that do not overlap with those specified in the exclusion list, such as Romanian (Moldova), Arabic (Syria), Tatar (Russia), etc. I’m here.

Initial access to a victim’s network is through Remote Desktop Protocol (RDP) exploitation, drive-by security breaches, phishing campaigns, exploitation of valid accounts, and weaponization of published applications.

Upon finding a successful entry point, the malware attempts to establish persistence, elevate privileges, perform lateral movement, log files, files in the Windows Recycle Bin folder, and purge shadow copies before starting its encryption routine. Follow the steps.

“LockBit affiliates have been observed using a variety of freeware and open source tools during intrusions,” the agencies said. “These tools are used for a variety of activities including network reconnaissance, remote access and tunneling, credential dumping, and file exfiltration.”

One of the defining features of this attack is the use of a custom extraction tool called StealBit. This is provided by LockBit Group to affiliates for double extortion purposes.

Ransomware gangs in particular were hit hard in late September 2022 when disgruntled LockBit developers released the builder code for LockBit 3.0, allowing other criminals to use the situation to launch their own variants. Concerns arose that it might produce seeds.

In November, the U.S. Department of Justice reported that LockBit ransomware stock was used against at least 1,000 victims worldwide to generate over $100 million in illicit profits.

Industrial cybersecurity company Dragos revealed earlier this year that LockBit 3.0 was responsible for 21% of the 189 ransomware attacks detected against critical infrastructure in Q4 2022, accounting for 40 I made it Most of these attacks affected the food, beverage, and manufacturing sectors.

The FBI’s Internet Crime Complaint Center (IC3) ranked LockBit (149), BlackCat (114), and Hive (87) as the top three ransoms to victimize critical infrastructure in 2022 in their latest Internet Crime Report. Listed as a wear subspecies.

webinar

Discover the hidden dangers of third-party SaaS apps

Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions granted and how to minimize the risks.

reserve a seat

The advisory comes several times after the BianLian ransomware group shifted its focus from encrypting victims’ files to pure data-stealing attacks and cybersecurity firm Avast released a free decryption tool in January 2023. It came out months later.

In a related development, Kaspersky has released a free decryption tool to help victims whose data was locked down by a version of ransomware based on the Conti source code leaked after Russia’s invasion of Ukraine last year. caused internal friction.

Intel 471 said last year, “Given the sophistication of LockBit 3.0 and Conti ransomware variants, it’s easy to forget that people are running these criminal enterprises.” It only takes one wrongdoing to unravel or disrupt a malicious operation.”

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *