A Deep-dive Analysis of LOCKBIT 2.0
ID: b507f826-98a3-551b-ab6c-627fd2cfeeeb
STIX ID: report--b507f826-98a3-551b-ab6c-627fd2cfeeeb
Feed Name: Cyble Blog
LOCKBIT 2.0 is a Ransomware-as-a-Service (RaaS) operation that performs double extortion by exfiltrating victim data (using tools such as StealBIT) and then encrypting files with a .lockbit extension; affiliates deploy customized variants and use Cobalt Strike, Metasploit, AD/LDAP enumeration, service termination, Defender policy modification, process injection, and VMware shared-folder propagation. The report provides static and dynamic analysis of a Windows x86 sample, describes victim-facing artifacts (ransom notes, desktop changes, TOR leak site), lists targeted/terminated services and a SHA-256 indicator, and offers defensive recommendations such as MFA, updates, AV, and offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
