CERT -FR, France's Computer Emergency Response Team, is warning about a new ransomware called Lockean, which is behind a series of attacks against French companies. The attacks have been ongoing for the past 2 years.

The list of targeted French organizations includes logistics company Gefco, pharmaceutical companies Fareva and Pierre Fabre, and the newspaper Ouest-France.
See also: Toronto: Public transit system reported ransomware attack
CERT-FR, part of the National Cybersecurity Agency of France (ANSSI), has published a detailed report on the activity of the Lockean ransomware gang, which appears to have been active since June 2020.
“Based on the incidents reported to ANSSI and its partners, investigations were carried out by the organization to confirm the existence of a criminal group responsible for these incidents and to understand its modus operandi, techniques, tactics and procedures (TTP),” the report published by CERT-FR states. “First observed in June 2020, the group called Lockean is believed to have been linked to several Ransomware-as-a-Service (RaaS) attacks.”

The Lockean ransomware group tends to target French entities according to the logic of Big Game Hunting.
See also: Ransomware targets companies during mergers and acquisitions
In almost all attacks attributed to the gang, CERT-FR researchers observed the involvement of the QakBot malware and the CobaltStrike post-exploitation tool . The ransomware operators distributed the malware via phishing emails .
The Lockean ransomware group used several tools for lateral movement into the networks of French companies, including AdFind, BITSAdmin , and BloodHound , and the RClone utility for data theft.
The Lockean group has used different ransomware strains over the past two years, including DoppelPaymer, Egregor, Maze, REvil , and ProLock.
See also: Cring ransomware: Continues attacks on industrial organizations
Due to the different ransomware, experts believe the group is what security researchers call a “ransomware affiliate,” a term that refers to criminal groups that subscribe to Ransomware-as-a-Service (RaaS) platforms.
The report published by CERT-FR provides further technical details about the attacks.
Source: securityaffairs.co
