The LockBit gang is relaunching its ransomware operation on a new infrastructure less than a week after law enforcement hacked their servers, and is threatening to focus more of their attacks on the government sector.
On Saturday, LockBit announced it was resuming the ransomware business and released damage control communication admitting that “personal negligence and irresponsibility” led to law enforcement disrupting its activity in Operation Cronos.
The gang kept the brand name and moved its data leak site to a new .onion address listing 12 new victims with countdown timers for publishing stolen information.
On February 19, the law enforcement agencies took down LockBit’s infrastructure, which included 34 servers hosting the data leak website and its mirrors, data stolen from the victims, cryptocurrency addresses, decryption keys, and the affiliate panel.
The administrator behind LockBit, in a lengthy follow-up message, said some of their websites were confiscated by most likely exploiting a critical PHP flaw tracked as CVE-2023-3824, acknowledging that they didn’t update PHP.
The gang confirmed the breach saying that they lost only the servers running PHP and that backup systems without PHP were untouched.
They also called for attacking the “.gov sector” more often, while also stating that the server from which the authorities obtained more than 1,000 decryption keys held almost 20,000 decryptors, most of which were protected and accounted for about half of the total number of decryptors generated since 2019.
Five days later, LockBit is back and provides details about the breach and how they are going to run the business to make their infrastructure more difficult to hack.
LockBit says they updated the PHP server and announced that they would reward anyone who finds a vulnerability in the latest version.
LockBit plans to upgrade security for its infrastructure and switch to manually releasing decryptors and trial file decryptions, as well as host the affiliate panel on multiple servers and provide its partners with access to different copies based on the trust level.
The long message from LockBit looks like damage control and an attempt to restore credibility for a lost reputation.

















Comments