LockBit ransomware is a popular and active ransomware group first detected in September 2019 and used by Threat Actors (TAs) to target multiple sectors and organizations worldwide.
According to CYBLE, Cyber Threat Intelligence Company, “We determine that over 1/3rd of the ransomware gang’s victims are from the BFSI sector, followed by the Professional Services sector.”
Cyble Research Labs came across a Twitter post wherein a researcher mentioned that a new version of ransomware named “LockBit 3.0” (also referred to as “LockBit Black”) is now active in the wild.
The recent blog post published by Cyble mention that LockBit 3.0 encrypts files on the victim’s machine and appends the extension of encrypted files as “HLJkNskOq.” LockBit ransomware requires a key from the command-line argument “-pass” to execute.
Experts say, the ransomware is encrypted and decrypts the strings and code during runtime, and resolves its API functions dynamically.
Subsequently, it creates a mutex to make sure that only one instance of malware is running on the victim’s system at any given time. The malware exits if the mutex is already present.
Experts mention that ransomware creates multiple threads to perform several tasks in parallel for faster file encryption. Each thread is responsible for querying system information, getting drive details, ransom note creation, getting file attributes, deleting services, file search, encryption, etc.
LockBit 3.0 ransomware deletes a few services to encrypt the files successfully. To delete these services, the ransomware calls the OpenSCManagerA() API to get the service control manager database access. At last, the ransomware changes the victim’s wallpaper.
Here the victims are instructed on how to pay the ransom to decrypt their encrypted files. Additionally, the TAs threatens the victims stating that their personal data will be posted on their leak site if the ransom is not paid within the specified window.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…