logo

Using the LockBit builder to generate targeted ransomware

ID: b02d0ed2-5bf4-5776-94ae-3baf2764e9ff

STIX ID: report--b02d0ed2-5bf4-5776-94ae-3baf2764e9ff

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2024-04-15

Date Updated: 2026-04-29

Author: Eduardo Ovalle, Francesco Figurelli, Cristian Souza, Ashley Muñoz

...
...

Kaspersky examines the leaked LockBit 3.0 builder and a real incident where attackers used stolen Administrator credentials to produce a custom LockBit variant that propagated via PsExec, disabled Windows Defender, deleted event logs, used Cobalt Strike and SessionGopher for credential harvesting, and caused network-wide encryption; the report dissects the builder/configuration, tests available decryption tools, maps global use of leaked builds, and recommends mitigations such as robust endpoint protection, MDR, credential controls, patching, and backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.