logo

LockBit Black & DragonForce: Unraveling The Link

ID: d8de82c3-8e0b-5725-91bf-a9f42e6328ad

STIX ID: report--d8de82c3-8e0b-5725-91bf-a9f42e6328ad

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2024-10-22

Date Updated: 2026-07-17

...
...

Cyble Research & Intelligence Labs identified a DragonForce ransomware binary active since November 2023 that employs double-extortion and publishes victim data on a leak site; analysis shows strong code similarities to LOCKBIT Black and likely reuse of a leaked LOCKBIT builder. The report includes technical details (process/service termination, unique file extension .AoVOpni2N, ransom note name pattern), IOCs (hashes), a YARA rule, MITRE ATT&CK mappings, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.