LockBit ransomware returns to attacks with new encryptors, servers

  • February 28, 2024
  •  
  • 01:31 PM
  •  
  • 0

Lockbit 3.0

The LockBit ransomware gang is once again conducting attacks, using updated encryptors with ransom notes linking to new servers after last week's law enforcement disruption.

Last week, the NCA, FBI, and Europol conducted a coordinated disruption called 'Operation Cronos' against the LockBit ransomware operation.

As part of this operation, law enforcement seized infrastructure, retrieved decryptors, and, in an embarrassing moment for LockBit, converted the ransomware gang's data leak site into a police press portal.

LockBit data leak site converted into a press site
LockBit data leak site converted into a press site
Source: BleepingComputer

Soon after, LockBit set up a new data leak site and left a long note addressed to the FBI, claiming law enforcement breached their servers using a PHP bug.

However, instead of rebranding, they promised to return with updated infrastructure and new security mechanisms to prevent law enforcement from performing operation-wide attacks and gaining access to decryptors.

Updated LockBit encryptors used in attacks

As of yesterday, LockBit appears to be conducting attacks again, with new encryptors and infrastructure setup for data leak and negotiation sites.

As first reported by Zscaler, the ransomware gang updated their encryptor's ransom notes with Tor URLs for the gang's new infrastructure. BleepingComputer later found samples of the encryptors uploaded to VirusTotal yesterday [Sample] (shared by MalwareHunterTeam) and today [Sample], containing the updated ransom notes.

BleepingComputer also confirmed that the operation's negotiation servers are live again but only work for victims of new attacks.

New LockBit negotiation sites
New LockBit negotiation sites
Source: BleepingComputer

At the time of LockBit's takedown, the ransomware operation had approximately 180 affiliates working with them to conduct attacks.

It is not known how many are still working with the Ransomware-as-a-Service, as one has publicly lashed out at the operation on X.

However, LockBit states that they are now actively recruiting experienced pentesters to join their operation again, which will likely lead to increased attacks in the future.

Whether this is a grand plan for LockBit to slowly fade away and rebrand as we saw with Conti remains to be seen. For now, though, it is safer to assume that LockBit continues to be a threat.

Search
Categories
Read More
Dell warns of data breach 49 million customers allegedly affected
As the database is no longer being sold, there is a good chance a threat actor is...
By AFFA 2024-05-09 18:37:57 0 1
ExpressVPN bug has been leaking some DNS requests for years
February 11, 2024   10:09 AM   0 ExpressVPN has removed the split...
By AFFA 2024-02-11 16:45:30 0 127
Recent Windows updates break Microsoft Connected Cache delivery
April 5, 2024   06:31 PM   0 Microsoft says Windows 10 updates...
By AFFA 2024-04-06 17:47:14 0 55
Microsoft fixes bug behind incorrect BitLocker encryption errors
April 29, 2024   11:04 AM   0 Microsoft has fixed a known issue...
By AFFA 2024-04-29 18:47:32 0 26
Windows 11 tips and tricks
Windows 11 comes with built-in capabilities that make your life easier. Learn how to use...
By AFFA 2024-03-11 17:04:55 0 102