LockBit Ransomware Continued to Impact Operational Technology (OT) in 2022
ID: 7538844c-18b0-5d74-8036-bf9c0c7e513f
STIX ID: report--7538844c-18b0-5d74-8036-bf9c0c7e513f
Feed Name: Dragos Blog
The report describes LockBit ransomware's evolution into a widely used ransomware-as-a-service (RaaS) operation that has grown since 2019 and surged since 2021, targeting numerous sectors—particularly industrial and critical-infrastructure-aligned organizations. It outlines victimology, technical capabilities (Windows/Linux/VMware/ESXi encryption, exfiltration, and the StealBit information-stealing tool), and typical infrastructure (TOR sites, secure messaging, affiliate interfaces), and directs readers to a whitepaper with detection and mitigation guidance for ICS/OT environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
