Cybercrime group Evil Corp has now switched to the LockBit ransomware operation on target networks to evade sanctions imposed by the US Treasury Department's Office of Foreign Assets Control (OFAC).
See also: Microsoft: Prevented attacks that abused OneDrive

Active since 2007, Evil Corp (also known as INDRIK SPIDER or the Dridex gang) is known for promoting the Dridex malware and later moving into the ransomware business.
The gang started with the Locky ransomware and then developed its own ransomware strain known as BitPaymer by 2019.
Since the US imposed sanctions on them in December 2019 for using Dridex to cause in financial losses , the group switched to deploying its new WastedLocker ransomware in June 2020.
See also: Atlassian Confluence zero-day: Actively used in attacks
As of March 2021, Evil Corp moved to another strain known as Hades ransomware, a 64-bit variant of WastedLocker that was upgraded with additional code obfuscation and minor feature.
Since then, threat actors have also impersonated the PayloadBin hacking group and used other ransomware strains known as Macaw Locker and Phoenix CryptoLocker.
The LockBit switch
As threat analysts at Mandiant recently observed, the cybercrime gang has made another attempt to distance itself from familiar tools that allow victims to pay ransoms without facing the risks associated with violating OFAC regulations.
A cluster of activities tracked by Mandiant as UNC2165 (which previously developed Hades ransomware and was linked to Evil Corp) is now developing ransomware as a subsidiary company called LockBit.
“Using this RaaS would allow UNC2165 to combine with other affiliates, requiring visibility into earlier stages of the attack lifecycle to properly attribute activity, compared to previous operations that might have been attributed based on the use of a dedicated ransomware,” Mandiant said.
“Furthermore, frequent patch updates and rebranding of HADES required development resources, and it is plausible that UNC2165 considered using LOCKBIT as a more cost-effective option.”

This new tactic of acting as a Ransomware as a Service (RaaS) would likely allow them to invest the time required for ransomware development into expanding the gang's ransomware development operations.
See also: Conti ransomware targeted Intel firmware for stealth attacks
Another theory is that switching to malicious tools may provide Evil Corp with enough free resources to develop a new ransomware strain from scratch, making it harder for security researchers to connect it to the gang's previous operations.
Information source: bleepingcomputer.com
