HomeSecurityLockbit ransomware: FBI provides details on the operation and protection tips

Lockbit ransomware: FBI provides details on the operation and protection tips

The FBI has published technical details and breach indicators related to attacks by the LockBit ransomware.

The gang behind the LockBit ransomware has been active since September 2019, when it launched as a ransomware-as-a-service (RaaS). Two years later, in June 2021, LockBit announced LockBit 2.0 RaaS on the data breach site.

Lockbit ransomware

The ransomware gang redesigned Tor sites and upgraded the malware, adding more advanced features (e.g. automatic encryption of devices in Windows domains via Active Directory group policies).

See also: $4.4 million stolen in attack on Meter blockchain infrastructure

The cybercriminals behind the Lockbit ransomware are now trying to recruit insiders, i.e. company employees/executives, to provide them with direct access to corporate networks via Virtual Private Network (VPN) and Remote Desktop Protocol (RDP). The hackers are promising large sums of money in return.

In January, it was discovered that LockBit also added a Linux variant that targets VMware ESXi servers.

Regarding the operation of LockBit ransomware, the FBI revealed that the malware comes with a hidden debug window that can be activated during the infection process, using the SHIFT + F1 keyboard shortcut.

Once displayed, it can be used to view real-time information about the encryption process and record the status of user data destruction.

Lockbit ransomware: FBI provides details on the operation and protection tips

FBI: Companies urged to report attacks related to LockBit ransomware

The FBI has asked administrators and cybersecurity professionals to share information about LockBit attacks targeting their companies' networks.

The FBI is seeking any information that can be shared, including boundary logs showing communication to and from foreign IP addresses, ransom note samples, communications with the threat actors, Bitcoin wallet information, etc.,” the federal agency said.

See also: BlackCat Ransomware: Link to BlackMatter, DarkSide Gangs

This way, the FBI will be able to more easily track malicious actors and coordinate with the private sector and the United States to prevent future attacks.

FBI

Protection: How to defend your network

The FBI also provides some tips that would help protect networks from LockBit ransomware:

  • Use strong and unique passwords for all accounts
  • Implement multi-factor authentication for all services (where possible)
  • Regular updating of all systems and software
  • Removing access to important data by multiple users
  • Use of firewalls
  • Enable protected files in the Windows Operating System to prevent unauthorized changes to critical files
  • Network segmentation to prevent the spread of LockBit ransomware
  • Identification, detection and investigation of abnormal activity with appropriate tools
  • Disable command-line and scripting activities
  • Keep offline data backups
  • All backup data must be encrypted and cover the entire organization's data infrastructure

See also: Sugar ransomware: New threat targets ordinary users/small businesses

Ransom payment?

The FBI also added that it does not encourage paying ransoms and advises companies not to do so. After all, it is not certain that the problem will be solved after paying.

Furthermore, giving in to ransomware gangs' demands is intensifying the attacks.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS