logo

Ransomware gangs and PR stunts: Why LockBit faked a ransomware attack against Mandiant

ID: 142be2eb-b549-520c-8e52-ff4a635c3624

STIX ID: report--142be2eb-b549-520c-8e52-ff4a635c3624

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2022-06-10

Date Updated: 2026-04-29

...
...

This report examines a LockBit public-relations stunt following Mandiant's attribution that linked a financially motivated cluster (UNC2165) associated with the sanctioned group Evil Corp to LockBit activity; LockBit published response files on its leak site to dispute the link and distance itself from Evil Corp, and the analysis highlights the legal and operational implications for victims and the broader ransomware ecosystem.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.