HomeSecurityLockBit ransomware: Encrypts Windows domains using group policies

LockBit ransomware: Encrypts Windows domains using group policies

A new version of LockBit 2.0 ransomware has been found that automates the encryption of a Windows domain using Active Directory group policies.

LockBit ransomware

The LockBit ransomware operation began in September 2019 as ransomware-as-a-service, where threat actors are hired to compromise networks and encrypt devices.

In return, recruited partners earn 70-80% of a ransom payment, and LockBit developers keep the rest.

Over the years, the ransomware operation has been very active, with a representative of the gang promoting the activity and providing support on hacking forums.

See also: Kaseya REvil ransomware: Company obtained decryption key

After banning ransomware topics on hacking forums, LockBit began promoting its new LockBit 2.0 ransomware-as-a-service feature on the data leak site.

The new version of LockBit includes many advanced features, two of which are described below.

Uses group policy update for network encryption

When threat actors compromise a network and eventually gain control of the domain controller, they use third-party software to develop scripts that disable antivirus and then execute ransomware on computers on the network.

In samples of the LockBit 2.0 ransomware discovered by MalwareHunterTeam and analyzed by BleepingComputer and Vitali Kremez, threat actors automated this process so that the ransomware is distributed across a domain when executed on a domain controller.

When executed, the ransomware will create new group policies on the domain controller which will then be pushed to every device on the network.

These policies disable Microsoft Defender real-time protection, alerts, sample submission to Microsoft, and default actions when malicious files are detected.

Other group policies are created, including one to create a scheduled task on Windows devices that launch the ransomware executable.

See also: Grief ransomware attack on the Municipality of Thessaloniki – What do the hackers want?

The ransomware will then execute the following command to push the Group Policy update to all computers in the Windows domain.

LockBit ransomware

Kremez told BleepingComputer that during this process, the ransomware will also use Windows Active Directory APIs to perform LDAP queries against the domain controller's ADS to obtain a list of computers.

Using this list, the ransomware executable will be copied to the desktop of each device, and the scheduled task configured by group policies will launch the ransomware using the UAC override shown below:

LockBit ransomware

As the ransomware will be executed using UAC bypass, the program will run silently in the background.

While MountLocker has previously used Windows Active Directory APIs to perform LDAP queries, this is the first time we've seen ransomware automate malware distribution via group policies.

See also: Babuk Locker ransomware: The gang's website was filled with porn images/GIFs

The ransom note is printed on all networked printers

LockBit 2.0 also includes a feature previously used by the Egregor Ransomware, which prints the ransom note to all networked printers.

When the ransomware has finished encrypting a device, it will repeatedly print the ransom note on any connected network printer to get the victim's attention, as shown below.

LockBit ransomware

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS