Cybercriminals Harness Leaked LockBit Builder in Wave of New Attacks
We Keep you Connected
Cybercriminals Harness Leaked LockBit Builder in Wave of New Attacks
Threat actors are using and customizing leaked Lockbit code to carry out their own ransomware attacks. Lockbit is arguably the world’s leading ransomware-as-a-service (RaaS) operation. Last June, it revealed its latest version 3 malware (also referred to as “Lockbit Black”), promising to “make ransomware great again.” And it followed through — the latest iteration significantly upgraded on its already powerful predecessors, most notably with sophisticated anti-analysis protections. The third Lockbit has since been deployed in major campaigns, like the recent attack against the largest port in Japan. Not all Lockbit attacks are carried out by Lockbit or its affiliates, however. After a developer leaked two versions of the builder code for Lockbit v3 last September, unaffiliated cybercriminals now appear to be adopting the cyber underground’s premier malware-making tool for their own ends. “It’s very common for other hackers to take advantage of ransomware and other malware programs once the toolkit or source has leaked. Most hackers are lazy and they will take the quickest, shortest route to ill-gotten gains,” said Roger Grimes, data-driven defense evangelist at KnowBe4, in a statement sent to Dark Reading. Last Fall, researchers from Kaspersky observed a cyber intrusion using a variant of Lockbit v3 to encrypt an organization’s critical systems. But the nature of the attack was not at all aligned with Lockbit’s M.O. In a ransom note, the perpetrators identified themselves as the “National Hazard Agency.” Their message was par for the course — “your data are encrypted,” “if you do not pay the ransom we will attack your company repeatedly again,” etc. They included an email and instant messaging contact details, and demanded $3 million paid in Bitcoin or Monero. (Major RaaS’ like Lockbit use their own bespoke platform for negotiating with victims.) Other researchers observed other groups using Lockbit around this time, but with their own twist on the ransom note, like in the low-grade example below:
Enhanced Expertise: Co-Managed services bring in specialized expertise to complement your IT team, helping them tackle complex issues and projects more effectively.
Resource Augmentation: It's not about replacing your IT department but augmenting their resources. This allows your IT team to focus on strategic initiatives while routine tasks are handled externally.
Scalability: Co-Managed services are scalable, so you can adjust the level of support as per your needs, ensuring efficient resource allocation.
Cybersecurity Boost: Co-Managed services often provide advanced cybersecurity solutions, which help protect your organization from cyber threats and vulnerabilities.
Cost-Efficiency: By outsourcing routine tasks and maintenance, your IT department can allocate resources more efficiently, potentially reducing overall IT costs.
Improved Compliance: Co-Managed services can assist with compliance management, ensuring your organization adheres to industry regulations and standards.
Risk Mitigation: Shared responsibility for IT operations means shared risk. Co-Managed services providers work alongside your IT team to minimize potential risks.
Strategic Partnerships: Partnering with experienced Co-Managed service providers can enhance your organization's reputation by showcasing a commitment to innovation and efficiency.
Faster Issue Resolution: Co-Managed services often have access to advanced tools and resources, enabling quicker problem-solving and issue resolution.
Customized Solutions: Tailored solutions mean that your IT department has more control over the services provided and can align them with your organization's specific needs.
Flexibility: Your IT team retains control and can collaborate closely with Co-Managed service providers, ensuring a seamless partnership.
Catering to All IT Issues So You Can Stay Connected Securely
The Network Company has been based in South Orange County, CA, for over 27 years and provides “Managed IT Services.” We support your company’s network, computers, software, and users; and make sure your system is always running smoothly. Our topmost priority is to ensure that your users and customers get the most from your IT investment.
GET YOUR FREE, NO-OBLIGATION NETWORK HEALTH CHECK! We know you’re so busy running your business that sometimes you may forget to think about the security and health of your computer network. In fact, many business owners do NOT perform regular IT and Security maintenance, leaving the door wide open for spyware, viruses and other malicious threats that can infect their networks. This can lead to the loss of irreplaceable business data and hours of downtime. This is where we can help with Professional IT services, no matter what industry your business is in.
We don’t want this to happen to you! We’re offering you a FREE, no-strings-attached Network Health Check, which includes an inventory of your current environment, along with recommended improvements to keep your network healthy.
What’s the catch? You must be wondering why we are willing to give this away for free. We are simply offering this Network Health Check as a risk-free way to “get to know us” while helping you identify areas of vulnerability.
How does it work? To get your free Network Health Check, simply click here to complete the online request form. After we receive your request, we will contact you to schedule a specialist to perform the assessment.
Following the assessment, you will receive a complimentary recommended action plan and estimate for correcting any existing issues.