HomeSecurityLockBit Green ransomware: New version is based on Conti source code

LockBit Green ransomware: New version based on Conti source code

The LockBit ransomware gang uses a new encryptor named Green, which is based on the source code of the Conti ransomware.

LockBit Green ransomware

The LockBit ransomware gang continues its malicious activity, this time developing an encryptor based on the previously leaked Conti ransomware source code. This is not the first time it has used encryptors associated with other ransomware operations.

Since the beginning of its malicious activities, the LockBit criminal organization has been continuously improving its encryption technology and tactics. It started with a custom system and evolved it into what is now LockBit 3.0 (aka LockBit Black), which is based on the source code of the BlackMatter ransomware.

See also: Hackers use IceBreaker malware to compromise gaming companies

This week, VX-Underground reported that the ransomware gang is now using “LockBit Green,” a new encryptor based on source code leaked by the Conti group. This shows that cybercriminals remain active and vigilant in their attempt to extort individuals and companies around the world.

After a series of devastating data breaches by the Conti gang, which led to the leak of 170,000 confidential messages and the source code of their encryption engine, many hackers took advantage of the opportunity and used the code to create their own encryption engines, even using them against Russian companies.

LockBit Green

Since news of the new LockBit Green broke, researchers have discovered samples of the new cryptographer on VirusTotal and other malware reporting platforms.

After reverse-engineering a sample of LockBit Green, CyberGeeksTech – a malware – assured BleepingComputer that, without a doubt, there is a connection to the Conti ransomware.

Conti ransomware

“I have analyzed the sample and it is 100% based on Conti's source code,” the researcher told BleepingComputer.

“The decryption algorithm is just one example of the similarity. It's strange that they chose to create a payload based on Conti, when they've had their own encryptor for some time“.

See also: Apple Maps: Bug may have allowed location data collection

Cybersecurity firm PRODAFT also revealed four MD5 hashes of LockBit Green samples, along with a Yara rule that can detect the new variant.

According to PRODAFT, at least five targets have already been attacked by the new LockBit Green.

Despite the similarities to Conti ransomware, the ransom notes have of course been modified to use the format used by LockBit 3.0 (instead of Conti).

However, it appears that LockBit Green uses what appears to be a random extension on encrypted files, instead of the standard .lockbit extension.

It's unclear why the LockBit gang is using a new encryptor based on Conti ransomware, when their own is working fine. However, PRODAFT may have the answer: "We particularly noticed that former Conti members preferred LockBit Green after the announcement. They probably feel comfortable using conti-based ransomware," PRODAFT told BleepingComputer.

See also: Consent-phishing attack passes Microsoft's 'Verified Publisher' checks

LockBit ransomware is steadily growing and continues to pose a threat to those who don’t take proper precautions online. With powerful encryption algorithms at its disposal, LockBit can easily lock up valuable data until victims pay for its “release” – something many people are unfortunately willing (or forced) to do. To protect yourself from LockBit or any other ransomware, be sure to invest in proper security training for yourself and your employees, as well as regularly patching systems and implementing MFA solutions where available!

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS