NotLockBit: A Deep Dive Into the New Ransomware Threat
ID: 9ece2704-4a65-52ce-a95c-0a15e36acacc
STIX ID: report--9ece2704-4a65-52ce-a95c-0a15e36acacc
Feed Name: Qualys Blog
Threat Score
NotLockBit is a newly observed Go-based ransomware family targeting macOS and Windows that collects system information, generates an RSA-encrypted master key, encrypts user and VM files with AES (renaming them with an .abcd extension), exfiltrates data to attacker-controlled AWS S3 storage, changes desktop wallpaper to a ransom banner, and self-deletes; the report includes sample hashes, targeted file extensions, detection/hunting queries, and IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
