HomeSecurityDragonForce ransomware: How is it related to LockBit?

DragonForce ransomware: How is it related to LockBit?

A new ransomware called DragonForce appears to be using the leaked LockBit ransomware builder

DragonForce ransomware LockBit

Specifically, the new hacking group is using a ransomware binary based on the exposed LockBit Black ransomware, according to the company Cyble.

Cyble has been investigating DragonForce ransomware activity for the past few months and shared its findings in a recent report.

DragonForce : Ransomware Builders leaks pose a threat

LockBit Black, also known as LockBit 3.0, is the third version of the popular LockBit. It was released in March 2022, and six months later the code was leaked by a disgruntled developer of the group.

LockBit administrators responded by launching a new version of their ransomware, named LockBit Green, but it was later reported to be a simple repurposed version of a Conti encryptor.

See also: Ransomware attack hits alcohol supplier Skanlog

Although the Cronos police operation destroyed the LockBit ransomware infrastructure in February 2024, the LockBit Black builder is still available for use. Furthermore, the ransomware has returned with a new infrastructure.

Cyble observed that the DragonForce group is leveraging the leaked LockBit Black builder to develop its own tools. The researchers came to this conclusion after observing striking similarities in the code structure and functionality of the DragonForce ransomware payload and LockBit Black.

DragonForce ransomware: How is it related to LockBit?

“The discovery of the DragonForce ransomware and its links to LockBit Black highlights the growing threat posed by the misuse of malware-building tools . The accessibility of such tools allows threat actors to customize and deploy ransomware payloads with ease, enhancing the threat landscape for organizations worldwide,” Cyble researchers wrote.

DragonForce ransomware: Who is behind it?

DragonForce ransomware was first detected in November 2023. The group typically uses the double extortion tactic (like most gangs) that involves encryption system. If the victim does not want to pay the ransom to decrypt their data (e.g. due to the existence of backups), the attackers threaten to leak the stolen data.

The group has claimed responsibility for several attacks, including those on the Ohio Lottery, Yakult Australia, and Coca-Cola Singapore.

See also: Megazord Ransomware attacks healthcare and government entities

There is also a group hacktivist called DragonForce, based in Malaysia, responsible for various malicious campaigns targeting government agencies and organizations across the Middle East and Asia. Although this group has announced that it wants to release its own ransomware in 2022, we do not know if they are the ones behind the DragonForce ransomware.

DragonForce ransomware: How is it related to LockBit?

Ransomware protection

Protecting against ransomware attacks requires preventative measures. One of these is informing and educating users to recognize and avoid suspicious emails or links that may contain malware.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

It is also important to keep the operating system and all installed programs up to date, as updates often include security fixes that can protect against new forms of ransomware (e.g. the new DragonForce).

See also: Hackers are using developing countries for new ransomware attacks

Backing up your data is essential to protect your most important data. Using reliable antivirus software is another important practice for protecting against ransomware attacks.

Finally, using tools to restrict user rights and implementing the principle of least privilege can help protect against attacks by limiting the malware's ability to extend its impact on the system.

Source: www.infosecurity-magazine.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS