HomeSecurityLockBit ransomware: LockBit 3.0 builder leaked on Twitter

LockBit ransomware: LockBit 3.0 builder leaked on Twitter

The notorious LockBit ransomware has suffered a major breach, as a disgruntled developer leaked the builder of the gang's newest encryptor, LockBit 3.0.

LockBit ransomware

In June, the gang behind the LockBit ransomware released version 3.0 of its encryptor, codenamed LockBit Black.

The hackers created this new version by adding new features that allow the ransomware to evade analysis, new extortion methods, and a ransomware bug bounty program.

See also: Optus hacked: Data breach of millions of Australians

However, it appears that LockBit has been compromised, with one or two people (it's not clear) leaking the LockBit 3.0 builder online.

LockBit ransomware: LockBit 3.0 builder leaked on Twitter

According to security researcher 3xp0rt, a recently registered user named “Ali Qushji” claims that his team hacked LockBits servers and found a builder for the LockBit 3.0 ransomware encryptor.

After researcher 3xp0rt shared the tweet about the leaked LockBit 3.0 builder, VX-Underground stated that a user named “protonleaks” contacted them on September 10th and also shared a copy of the builder. The leaker may be the same in both cases, but may be using different names. We don’t know which is which at this time.

However, VX-Underground says that LockBitSupp, the public spokesperson for the LockBit ransomware gang, claims that there was no breach, but rather a disgruntled developer leaked the private ransomware builder.

See also: Predator surveillance: This is how they targeted politicians, citizens and companies!

“We contacted the Lockbit ransomware group about this and discovered that the leaker was a developer employed by the Lockbit ransomware group,” VX-Underground shared in a now-deleted tweet.

“They were upset with Lockbit's leadership and leaked the ransomware builder“.

According to BleepingComputer, multiple security confirmed that the builder was authentic.

LockBit 3.0 builder

What does the ransomware builder leak mean?

This leak does not only have negative effects on the LockBit ransomware gang. It has serious implications for the security of organizations and businesses, as many cybercriminals could use the builder to carry out their own attacks.

The leaked LockBit 3.0 builder allows anyone to quickly create the executables needed to launch their own malicious enterprise, including an encryptor, a decryptor, and specialized tools.

The builder consists of four files: encryption key generator, builder, a modifiable configuration file, and a batch file for generating all the files.

See also: Windows 11: Provides better protection against SMB brute-force attacks

The included 'config.json' can be used to customize an encryptor, including modifying the ransom, changing configuration options, deciding whether to terminate processes and services, etc.

By modifying the configuration file, any cybercriminal can adapt it to their own needs.

This is not the first time a ransomware builder or ransomware source code has been released online. In June 2021, the Babuk ransomware builder was leaked, allowing anyone to create encryptors and decryptors for Windows and VMware ESXi, which other threat actors were using in attacks.

In March 2022, when the Conti suffered a data breach, their source code was also leaked online and was quickly used by the NB65 hacking group for ransomware attacks in Russia.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS