Unpicking LockBit — 22 Cases of Affiliate Tradecraft
ID: 45d44ee8-21b2-57f5-9094-ab093d2ba2cb
STIX ID: report--45d44ee8-21b2-57f5-9094-ab093d2ba2cb
Feed Name: DataBreaches.Net
Secureworks outlines how the GOLD MYSTIC group operated the LockBit RaaS since 2019, compromising thousands of organizations and employing varied TTPs such as manual and domain controller–driven ransomware deployment, data-theft extortion without encryption, and targeting VMware ESXi environments; it also notes copycats using the LockBit brand. The brief references the Feb 19, 2024 international law-enforcement disruption led by the UK NCA and US FBI against LockBit infrastructure and links to the full Secureworks report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
