LockBit 3.0 Variant Generates Custom, Self-Propagating Malware
ID: 5de90c09-da08-5979-9c60-b91dc8153251
STIX ID: report--5de90c09-da08-5979-9c60-b91dc8153251
Feed Name: Dark Reading
Date Published: 2024-04-16
Date Updated: 2026-04-21
Author: Jeffrey Schwartz, Contributing Writer
Kaspersky responded to an attack in West Africa that used a customized LockBit 3.0-derived ransomware variant created from a leaked builder; the malware disabled Windows Defender, encrypted network shares, deleted event logs, and could target specific systems and file types. The report warns the leaked builder enables less-skilled actors to produce potent, self-propagating ransomware and recommends standard mitigations such as EDR/MDR, MFA, network segmentation, application whitelisting, and tested backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
