LockBit Black & DragonForce: Unraveling The Link
ID: d8de82c3-8e0b-5725-91bf-a9f42e6328ad
STIX ID: report--d8de82c3-8e0b-5725-91bf-a9f42e6328ad
Feed Name: Cyble Blog
Cyble Research & Intelligence Labs identified a DragonForce ransomware binary active since November 2023 that employs double-extortion and publishes victim data on a leak site; analysis shows strong code similarities to LOCKBIT Black and likely reuse of a leaked LOCKBIT builder. The report includes technical details (process/service termination, unique file extension .AoVOpni2N, ransom note name pattern), IOCs (hashes), a YARA rule, MITRE ATT&CK mappings, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
