0% found this document useful (0 votes)
65 views3 pages

LockBit Ransomware: Threat Overview and Defense

LockBit ransomware operates as a RaaS model, utilizing purchased access and vulnerabilities to breach systems and encrypt data with strong ciphers. It employs double extortion by threatening data leaks if ransom isn't paid, which can cause complete data loss and disruption. Defense requires strong security, patching, backups, and incident response plans. LockBit was first seen in 2019 and has since evolved through multiple versions, becoming the most active ransomware in 2022 by targeting small businesses.

Uploaded by

yuvraj
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
65 views3 pages

LockBit Ransomware: Threat Overview and Defense

LockBit ransomware operates as a RaaS model, utilizing purchased access and vulnerabilities to breach systems and encrypt data with strong ciphers. It employs double extortion by threatening data leaks if ransom isn't paid, which can cause complete data loss and disruption. Defense requires strong security, patching, backups, and incident response plans. LockBit was first seen in 2019 and has since evolved through multiple versions, becoming the most active ransomware in 2022 by targeting small businesses.

Uploaded by

yuvraj
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

LockBit Ransomware March 27th, 2024

New finds
this week
What Is
LockBit
Ransomwa
re?
__

Cybervie
Explore
cybersecuri
ty careers,
training for
smooth
transition,
and
competitive
salaries

What Is LockBit Ransomware?


-Yuvraj Singh

LockBit ransomware operates as a RaaS model with affiliates using purchased access,
unpatched weaknesses, or potentially insider info to breach systems. The attack unfolds in
two stages: initial compromise and gathering intel, followed by encryption with a strong
cipher. LockBit utilizes double extortion, stealing data alongside encryption and threatening
to leak it if the ransom isn't paid. This can lead to complete data loss, operational disruption,
and reputational damage. Defense involves strong endpoint security, prompt patching,
multi-factor authentication, following the 3-2-1 backup rule, and an incident response plan
with segmentation to limit spread. Cybersecurity professionals must stay updated on
LockBit's tactics and the evolving threat landscape.

LockBit ransomware has been implicated in more cyberattacks this year than any other
ransomware, making it the most active ransomware in the world. And while the average
ransomware payment is nearly $1 million per incident, LockBit victims pay an average ransom
of approximately $85,000—indicating that LockBit targets small-to-medium-sized
organizations. LockBit was first observed in September 2019. Since then, it has evolved:
LockBit 2.0 appeared in 2021; LockBit 3.0, the current version, was discovered in June 2022.
LockBit seeks initial access to target networks primarily through purchased access,
unpatched vulnerabilities, insider access, and zero-day exploits. “Second-stage” LockBit
establishes control of a victim's system, collects network information, and achieves primary
goals such as stealing and encrypting data. LockBit attacks typically employ a double
extortion tactic to encourage victims to pay, first, to regain access to their encrypted files and
then to pay again to prevent their stolen data from being posted publicly. When used as a
Ransomware-as-a-Service (RaaS), an Initial Access Broker (IAB) deploys first-stage malware
or otherwise gains access within a target organization’s infrastructure. They then sell that
access to the primary LockBit operator for second-stage exploitation.

Who Is the LockBit Gang?


The LockBit gang considers itself the “Robin Hood” of ransomware groups. While the FBI has
not directly implicated the LockBit group as Russian, an assessment of LockBit’s public
communications—which espouse a broadly anti-Western political view—indicates they have
Russian origins with global affiliates. The group promotes the so-called “ethical” use of
ransomware and claims they won’t target healthcare, education, charitable, or social service
organizations. The LockBit gang maintains a dark web portal on The Onion Router (TOR)
network where they recruit talent and release the data of victims who refuse to meet their
demands. The LockBit group assures victims that those who pay their ransom will have their
data returned; establishing this is part of their business model.

How LockBit Ransomware Works (TT&P)


LockBit 2.0 seeks initial access to target networks primarily through purchased access,
unpatched vulnerabilities, insider access, and zero-day exploits. In LockBit’s RaaS model, the
primary operating group recruits Initial Access Brokers (IAB) through advertisements on the
dark web to obtain stolen credentials for Remote Desktop Protocol (RDP) or Virtual Private
Network (VPN) access. The LockBit group also develops exploits for known software
vulnerabilities to take advantage of unpatched or misconfigured enterprise networks. After
gaining initial access, LockBit 2.0 malware downloads C2 tools appropriate for the target
environment. LockBit 2.0’s second-stage C2 malware uses standard penetration testing tools
such as Cobalt Strike Beacon, MetaSploit, and Mimikatz, as well as custom exploit code. Like
Conti, LockBit 2.0 can spread within a target network using worm-like functionality. LockBit
2.0 malware source code is also notorious for protecting itself from analysis by security
researchers; tools are encrypted by default and only decrypted when a suitable environment
has been detected.

LockBit 2.0
Targets LockBit 2.0 primarily targets Windows systems, although some newer variations have
been modified to attack Linux-based data center virtualization environments, including
VMWare ESXi virtual machines. The malware is designed to attack victims in the United
States, Canada, Europe, Asia, and Latin America. LockBit 2.0 ignores systems in the
Commonwealth of Independent States and most Eastern Europe nations, with the notable
exception of Ukraine. LockBit typically targets mid-sized organizations. This may be due to
LockBit’s unique RaaS model, which makes it easy for a disgruntled insider to act as an IAB,
set their price, and collect ransom directly.

What a LockBit 2.0 Attack Looks Like


LockBit 2.0 IABs deploy an application known as “Stealbit” to attack a victim’s files with a
customizable set of target file extensions. After targeted files have been copied to an
attacker-controlled server, LockBit 2.0 installs itself in the Windows Registry as an automated
boot process to maintain persistence so that it will auto-start when the computer is rebooted.
LockBit 2.0 also tries to move laterally through a network via connections to other hosts to
deploy the ransomware on other machines. Then the malware installs a custom icon file and
proceeds with multi-threaded encryption using a pair of ECC (Curve25519) session keys, with
the private key encrypted with an ECC public key stored in the Windows Registry. Earlier
versions of LockBit appended a “.acbd” file extension to differentiate ransomed files; newer
versions use a “.lockbit” extension. Finally, LockBit changes the desktop wallpaper to the
signature LockBit ransom warning image and a ransom note titled “[Link]” is
dropped in each affected directory.

How to Protect Against LockBit Ransomware


Preventing a successful LockBit 2.0 attack requires effective cybersecurity and maintaining
an effective backup strategy that includes encrypted offline and offsite backups. To mitigate
the risk of a LockBit breach, implement robust access controls with strong password policies
and multi-factor authentication, maintain a vulnerability management program that ensures
security updates are applied when they are released, and architect internal networks with
critical resources segmented. Additionally, enable “Protected Files” in the Windows Operating
System to ensure that LockBit cannot alter critical system files. CylanceOPTICS Prevents
LockBit

Common questions

Powered by AI

Since its first appearance in 2019, LockBit ransomware has undergone significant evolution with the introduction of LockBit 2.0 in 2021 and 3.0 in 2022. These updates have introduced enhanced capabilities such as more efficient encryption, broader targeting capacities, and improved persistence mechanisms. LockBit's ability to adapt, including developing exploits for known vulnerabilities and expanding its target system types (like Linux-based environments), suggests increasing sophistication and diversity in ransomware threats. This implies that future ransomware may develop even more advanced evasion techniques, spectrum of targets, and potentially more aggressive extortion methods, influencing how cybersecurity defenses must also evolve to counteract these growing threats .

Organizations can defend against LockBit ransomware by implementing strong endpoint security measures, ensuring all software is up-to-date with patches, employing multi-factor authentication, and following the 3-2-1 backup rule for data safety. Additional security includes robust access control policies with strong passwords, network segmentation of critical resources, and enabling 'Protected Files' in Windows Operating Systems. These measures help in reducing exposure to ransomware by making it harder for LockBit to initially access networks and spread within them. While no solution is foolproof, these strategies significantly lower the risk of a LockBit breach and mitigate potential damages .

LockBit ransomware's focus on mid-sized organizations reflects a strategic acknowledgment of these entities typically having fewer resources and often being less fortified against cyber threats compared to large enterprises. This makes them attractive targets as they may be more likely to pay a ransom quickly to resolve disruptions without publicizing the attack. This strategy also highlights how cybercriminals exploit gaps in cybersecurity measures within potentially softer targets, contributing to a broader trend where small to medium-sized businesses are increasingly targeted due to perceived vulnerabilities within the current cyber threat landscape .

LockBit ransomware utilizes dark web networks to recruit Initial Access Brokers (IABs) and affiliates. Through advertisements on these platforms, it solicits individuals who can gain access to potential victims' networks, typically offering financial incentives for network credentials. This method not only broadens the group's reach by decentralizing the first-stage infiltration but also complicates efforts by authorities to trace and shut down operations owing to the anonymity provided by dark web transactions. It indicates a shift in how cybercrime syndicates operate, leveraging anonymity and broad networks to execute their schemes with reduced risk of detection .

LockBit's extensive use and status as the most active ransomware highlight its influence on global cybercrime trends by setting a precedent for highly organized and effective cybercriminal operations. Its operational model as RaaS facilitates widespread adaptation and replication. This proliferation suggests that ransomware will continue to dominate the cyber threat landscape, with potential future developments seeing more sophisticated techniques, increased targeting of cloud-based services and decentralized systems, and further specialization within cybercrime syndicates. Additionally, LockBit's impact compels a rethinking of cybersecurity policies and reinforces the need for global cooperation and shared intelligence in countering such pervasive threats .

Security researchers may face significant challenges in analyzing LockBit 2.0 due to its use of default encryption to protect itself from analysis. The ransomware only decrypts itself when it detects a specific environment, complicating efforts to study its source code. Furthermore, LockBit 2.0 employs sophisticated techniques and tools that are typically used for legitimate pen-testing, such as Cobalt Strike Beacon and Mimikatz, requiring researchers to distinguish malicious activity from potentially benign use. These factors create barriers in reverse-engineering the malware to develop countermeasures and understanding its full functionality and impact .

LockBit ransomware exhibits several features contributing to its resilience against typical cybersecurity defenses. These include its use of advanced encryption for both the ransomware code and encrypted data, preventing easy decryption without the correct keys. It also employs worm-like functionality to ensure widespread network penetration and utilizes standard, often legitimate, penetration testing tools for lateral movement, complicating detection and remediation. Its ability to operate stealthily and adapt to different environments, coupled with multi-threaded execution and automated persistence mechanisms, makes defending against it challenging. These aspects underscore the sophisticated nature of LockBit in evading defenses .

LockBit ransomware claims not to target healthcare, education, charitable, or social services, positioning itself as a 'Robin Hood' group. This self-presentation creates an ethical dilemma as it suggests a code of ethics or a moral stance amidst illegal activities. The claimed selective targeting attempts to justify or mitigate the perceived harm by only attacking commercial organizations. However, this does not absolve the broader implications of immorality and illegality in extortion, personal data theft, and disruption of operations. Moreover, the legitimacy of such claims is questionable, as distrust in the group’s adherence to these principles persists among potential victims. This self-characterization raises questions on ethics in cybercrime and the moral contradictions within illegal activities .

LockBit ransomware operates as a Ransomware-as-a-Service (RaaS), meaning the developers provide the ransomware infrastructure to affiliates or partners, who can then use it for attacks. Affiliates typically gain initial access through methods like purchased access, exploiting unpatched vulnerabilities, insider threats, or zero-day exploits. The attack unfolds in two stages: an initial compromise to gather information, and then encryption using a strong cipher. LockBit employs double extortion tactics where stolen data is encrypted and a threat is made to release it publicly if the ransom isn't paid. This model allows for lower ransom demands, targeting small to medium-sized organizations that might pay quickly without seeking professional security help. As a result, it has led to increased frequency of attacks and operational disruptions in targets, with the average ransom being around $85,000 .

Once LockBit gains initial access to a network, it installs itself in the Windows Registry as an automated boot process to ensure it can restart after system reboots, maintaining persistence. The malware utilizes tools commonly used in penetration testing, such as Cobalt Strike Beacon, MetaSploit, and Mimikatz, along with proprietary custom exploit code. These tools aid in lateral movement across a network by exploiting existing vulnerabilities and exploiting misconfigurations to spread the ransomware to other systems. Additionally, LockBit's source code is safeguarded from analysis by default encryption, only decrypting in suitable environments .

You might also like