HomeSecurityLockBit: Still the most serious ransomware threat

LockBit: Still the most serious ransomware threat

According to a new report from ZeroFox, LockBit ransomware continues to be the top threat when it comes to digital extortion.

LockBit ransomware

Researchers found that LockBit was used in more than a quarter of global attacks ransomware and digital extortion (R&DE) from January 2022 to September 2023. The analysis showed that LockBit was responsible for 30% of all such attacks in Europe and 25% in North America.

However, ZeroFox said that the overall percentage of attacks represented by LockBit is on a downward trajectory. This is likely due to the increasing diversification of the R&DE landscape, with ransomware-as-a-service (RaaS) offerings lowering the barriers to entry for threat actors.

LockBit ransomware and North America

The researchers noted that LockBit was not used as frequently in attacks against North America compared to other regions, such as Europe. However, there was an increase in attacks during the time period mentioned above and it is believed that the percentage of victims will increase further by the end of 2023.

See also: Royal Mail: Spent £10 million on cybersecurity measures after LockBit attack

The industries most targeted by the LockBit gang in North America between January 2022 and September 2023 were manufacturing, construction, retail, legal and consulting services , and healthcare.

LockBit: Still the most serious ransomware threat

LockBit ransomware: Distribution and infection methods

The main techniques for distributing and deploying ransomware on victims' networks include:

Exploiting applications exposed on the Internet: Hackers exploit vulnerabilities in software that allowed remote code execution and gaining more privileges on vulnerable systems.

Phishing emails/messages: Affiliates of the LockBit gang used various lures in phishing attacks to gain access to victims. The malicious emails typically contained attachments and malicious links to infect victims.

External remote services: Threat actors leverage legitimate user credentials obtained through credential harvesting to gain access to external-facing remote working services.

Drive-by Compromise: Hackers gain access to systems through a user visiting a website, often targeting the user's web browser.

Use of valid accounts: Threat actors often compromise credentials to bypass access controls, create persistence, escalate privileges, and evade detection.

Although the percentage of R&DE attacks related to LockBit ransomware is decreasing, ZeroFox expects ransomware to remain one of the biggest threats to all types of organizations around the world.

See also: Allen & Overy: Law firm falls victim to LockBit attack

LockBit ransomware

The LockBit ransomware was first identified in September 2019. The ransomware is known for its speed of system compromise and its ability to spread within a compromised network.

This ransomware is said to be behind some recent major attacks, including those on Royal Mail, Boeing, and the Industrial and Commercial Bank of China (ICBC).

LockBit: Still the most serious ransomware threat

Protection against LockBit ransomware

To protect yourself from LockBit ransomware attacks, you should take a multi -layered approach . This includes installing strong antivirus software on all devices , regularly updating and patching software and operating systems, and using strong and unique passwords for all accounts. It is also important to regularly back up critical data and store it offline or on a separate network. Additionally, organizations should educate their employees about phishing emails and other social engineering tactics commonly used to distribute ransomware. By training employees to recognize and report suspicious emails or links, organizations can reduce the risk of falling victim to LockBit ransomware.

Another important LockBit ransomware protection measure is the implementation of network segmentation. By dividing the network into smaller, isolated segments, organizations can limit the spread of ransomware in the event that one segment is compromised. This can help limit the impact of an attack and prevent it from affecting the entire network.

See also: LockBit ransomware: Exploits Citrix Bleed vulnerability in attacks

It is also important to have an incident response planin place, which outlines the steps to take in the event of a ransomware attack. This plan should include procedures for isolating infected systems, notifying the appropriate authorities, and restoring data from backups.

Finally, organizations should stay up to date on the latest threats and security vulnerabilities.

By adopting a proactive and comprehensive approach to cybersecurity, organizations can significantly reduce the risk of falling victim to LockBit ransomware and other similar threats.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS