logo

NotLockBit: A Deep Dive Into the New Ransomware Threat

ID: 9ece2704-4a65-52ce-a95c-0a15e36acacc

STIX ID: report--9ece2704-4a65-52ce-a95c-0a15e36acacc

Feed Name: Qualys Blog

Threat Score
75/100

Date Published: 2024-12-18

Date Updated: 2026-04-28

Author: Pranita Pradeep Kulkarni

...
...

NotLockBit is a newly observed Go-based ransomware family targeting macOS and Windows that collects system information, generates an RSA-encrypted master key, encrypts user and VM files with AES (renaming them with an .abcd extension), exfiltrates data to attacker-controlled AWS S3 storage, changes desktop wallpaper to a ransom banner, and self-deletes; the report includes sample hashes, targeted file extensions, detection/hunting queries, and IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.