The notorious LockBit ransomware gang has announced that it is improving its defenses against attacks distributed denial-of-service (DDoS) and is threatening to adopt a triple blackmail tactic on its victims.

The gang recently suffered a DDoS attack, likely linked to cybersecurity firm Entrust . On June 18, the LockBit group used its ransomware to breach Entrust, stealing data at the same time . The company confirmed the incident and that data had been stolen. However, Entrust did not pay the ransom, and LockBit announced that it would publish all of the stolen data on August 19. This did not happen, however, because the gang’s leak site was hit by a DDoS attack. The gang believes the attack is linked to Entrust.
See also: Wiretapping Greece: Researchers reveal mass surveillance of telecommunications providers!
If this is indeed the case, it would be unprecedented and it is unlikely that Entrust would ever admit to carrying out such aggressive operations, since we are talking about a legitimate cybersecurity company.
Despite being quite common in cybersecurity, attacks are illegal and it would be unlikely for a legitimate company to admit to carrying out such attacks.
Another theory is that it could be a rival ransomware gang trying to hit LockBit.
In any case, we do not currently know who is behind the attack.
LockBit ransomware: Triple blackmail tactic
A few days ago, LockBitSupp, the public figurehead of the LockBit ransomware operation, announced that the gang is returning to its activities with a larger infrastructure that will provide access to data, without being affected by DdoS attacks and other similar incidents.
The DDoS attack that temporarily halted the Entrust data leak was seen as an opportunity to explore the triple blackmail tactic, to put more pressure on victims to pay ransom.
See also: LockBit 3.0 strengthens its dominance of the ransomware ecosystem
Initially, ransomware gangs encrypted systemsso that data could not be accessed without a decryption key provided by the hackers after the ransom was paid. However, many victims used backups to recover and thus did not pay the ransom. To apply more pressure, ransomware gangs also started stealing data from victims’ systems (before encryption) and threatening to publish it online if the ransom was not received. This is known as a double blackmail tactic and is very popular among ransomware gangs.
Now, however, the LockBit ransomware gang seems to be getting even more aggressive, wanting to adopt the triple extortion tactic, adding DDoS attacks as an extortion tactic in addition to encryption and theft and leakage.
“I am looking for dudosers [DDoSers] in the team, probably now we will attack targets and provide triple extortion, encryption + data leakage + dudos, because I have felt the power of dudos and how it invigorates and makes life more interesting,” LockBitSupp wrote in a post on a hacking forum.
Entrust: Data Leak
The gang also promised to torrent 300GB of data stolen from Entrust so that “the whole world would know its secrets.”

It seems the group has kept its promise and this weekend released a torrent called “entrust.com” with of files . The torrent is not only available on the gang’s data leak site but also on at least two file hosting services, one of which is no longer making it available.
See also: French hospital sends patients to other providers due to ransomware
LockBit ransomware: Defense against DdoS
As mentioned above, after the recent DDoS incident that affected the group, it was decided to strengthen its defenses. One method that has already been implemented to prevent further DDoS attacks is the use of unique links in ransom notes for victims. The gang said that it will take other measures as well.
LockBit ransomware has been active for almost three years. The gang claims more than 700 victims.
Source: www.bleepingcomputer.com
