HomeSecurityCERT-FR: Warns of Lockean ransomware attacks against French companies

CERT-FR: Warns of Lockean ransomware attacks against French companies

CERT -FR, France's Computer Emergency Response Team, is warning about a new ransomware called Lockean, which is behind a series of attacks against French companies. The attacks have been ongoing for the past 2 years.

Lockean ransomware of French companies

The list of targeted French organizations includes logistics company Gefco, pharmaceutical companies Fareva and Pierre Fabre, and the newspaper Ouest-France.

See also: Toronto: Public transit system reported ransomware attack

CERT-FR, part of the National Cybersecurity Agency of France (ANSSI), has published a detailed report on the activity of the Lockean ransomware gang, which appears to have been active since June 2020.

Based on the incidents reported to ANSSI and its partners, investigations were carried out by the organization to confirm the existence of a criminal group responsible for these incidents and to understand its modus operandi, techniques, tactics and procedures (TTP),” the report published by CERT-FR states. “First observed in June 2020, the group called Lockean is believed to have been linked to several Ransomware-as-a-Service (RaaS) attacks.”

CERT-FR

The Lockean ransomware group tends to target French entities according to the logic of Big Game Hunting.

See also: Ransomware targets companies during mergers and acquisitions

In almost all attacks attributed to the gang, CERT-FR researchers observed the involvement of the QakBot malware and the CobaltStrike post-exploitation tool . The ransomware operators distributed the malware via phishing emails .

The Lockean ransomware group used several tools for lateral movement into the networks of French companies, including AdFind, BITSAdmin , and BloodHound , and the RClone utility for data theft.

The Lockean group has used different ransomware strains over the past two years, including DoppelPaymer, Egregor, Maze, REvil , and ProLock.

See also: Cring ransomware: Continues attacks on industrial organizations

Due to the different ransomware, experts believe the group is what security researchers call a “ransomware affiliate,” a term that refers to criminal groups that subscribe to Ransomware-as-a-Service (RaaS) platforms.

The report published by CERT-FR provides further technical details about the attacks.

Source: securityaffairs.co

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS