logo

Tales From the Trenches; a Lockbit Ransomware Story

ID: 09bd9ebd-5712-5c49-a8ff-69c05216962b

STIX ID: report--09bd9ebd-5712-5c49-a8ff-69c05216962b

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2020-05-01

Date Updated: 2026-04-28

Author: ATR Operational Intelligence Team

...
...

This McAfee/Northwave report documents a real-world LockBit targeted ransomware incident and provides a full technical breakdown: initial access by brute-forcing an exposed administrator account, automated SMB lateral movement and deployment via a .NET dropper disguised as a PNG, UAC bypasses and process-injection techniques, shadow copy deletion and service/process termination, ransom note/helpdesk interaction, sample-based IOCs, and observations on LockBit development and underground distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.