LockBit Ransomware Evolves: New Stealthy Tactics Use DLL Sideloading & Masquerading to Bypass Defenses
ID: aad3d313-27f5-5bb3-b325-93106efdc552
STIX ID: report--aad3d313-27f5-5bb3-b325-93106efdc552
Feed Name: securityonline.info
The report details LockBit ransomware's evolved TTPs — notably DLL sideloading, process masquerading, and PowerShell-based AES+RSA encryption — and outlines a typical attack chain (initial access via remote tools, privilege escalation, discovery, credential theft, lateral movement, and file encryption). It highlights operational impact (large extortion, FBI attribution) and warns that the leak of the LockBit 3.0 builder has democratized deployment, increasing the threat to organizations globally.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
