Using the LockBit builder to generate targeted ransomware
ID: b02d0ed2-5bf4-5776-94ae-3baf2764e9ff
STIX ID: report--b02d0ed2-5bf4-5776-94ae-3baf2764e9ff
Feed Name: Securelist by Kaspersky
Date Published: 2024-04-15
Date Updated: 2026-04-29
Author: Eduardo Ovalle, Francesco Figurelli, Cristian Souza, Ashley Muñoz
Kaspersky examines the leaked LockBit 3.0 builder and a real incident where attackers used stolen Administrator credentials to produce a custom LockBit variant that propagated via PsExec, disabled Windows Defender, deleted event logs, used Cobalt Strike and SessionGopher for credential harvesting, and caused network-wide encryption; the report dissects the builder/configuration, tests available decryption tools, maps global use of leaked builds, and recommends mitigations such as robust endpoint protection, MDR, credential controls, patching, and backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
