The infamous LockBit ransomware variant has extorted almost $100m from US victims alone since January 2020.
The US Cybersecurity and Infrastructure Security Agency (CISA), UK National Cyber Security Centre (NCSC) and their Australian, New Zealand, Canadian, French and German equivalents revealed this in an advisory after warning of the continued threat posed by the collective.
LockBit was the most deployed ransomware of 2022 and continues to be prolific to this day. In US alone it has accounted for around 1700 attacks since 2020.
LockBit ransomware emerged in September 2019 as a ransomware-as-a-service (RaaS) operation and resurfaced as the LockBit 2.0 RaaS in June 2021 in response to the ban on ransomware groups on cybercrime forums.
Since January 2020, affiliates of the ransomware-as-a-service outfit have targeted numerous organizations of multiple critical infrastructure sectors, including financial services, food and agriculture, education, energy, government and emergency services, healthcare, manufacturing and transportation.
The advisory provided technical details on how the ransomware and its leak site have evolved over time, including the freeware and open-source tools typically used in post-intrusion activity and a detailed MITRE ATT&CK mapping of over 40 Tactics, Techniques, and Procedures (TTPs) employed by LockBit affiliates in attacks.
The authorities shared commonly observed vulnerabilities and how secondary ransomware attacks work when upstream supply chain victims are targeted.
The joint advisory also provides recommended mitigation measures to help defenders thwart LockBit activity targeting their organizations.
Image Credits : Tehtris














Comments