logo

Once Bitten: LockBit Ransomware Case Study

ID: d5276bbf-64bc-5367-b45c-3925916598f9

STIX ID: report--d5276bbf-64bc-5367-b45c-3925916598f9

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2023-05-04

Date Updated: 2026-04-29

...
...

ReliaQuest details a LockBit ransomware intrusion where initial access was gained through a SocGholish infection, Cobalt Strike was staged for C2 and lateral movement, and the adversary ultimately obtained administrator-level credentials to deregister EDR sensors and deploy an encryptor via GPO and PsExec, disabling defenses and deleting recovery artifacts; the report also maps observed MITRE techniques and provides detection/remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.