logo

LockBit ransomware group assemble strike team to breach banks, law firms and governments.

ID: 7d84cb45-a584-549e-be82-0d9406a0c626

STIX ID: report--7d84cb45-a584-549e-be82-0d9406a0c626

Feed Name: DoublePulsar

Threat Score
88/100

Date Published: 2023-11-13

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

LockBit has organized strike teams exploiting the Citrix NetScaler 'CitrixBleed' vulnerability to bypass MFA and gain internal remote-desktop-style access; they deploy remote access tools (notably Atera) to persist after patching, escalate privileges, disable EDR, steal data and deploy ransomware against large enterprises (including law firms and banks). Thousands of unpatched appliances remain exposed, multiple high-profile victims are being extorted (with at least one reported ransom payment), and the report stresses urgent enterprise patching, vendor accountability and law-enforcement action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.