Since last month, millions of emails have been sent via the Phorpiex botnet as part of a large campaign aimed at distributing the LockBit Black ransomware.

According to the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC), attackers are using phishing emails with ZIP containing an executable file that deploys the LockBit Black payload attachments . This, in turn, encrypts victims' systems if launched
See also: INC Ransom: Is the ransomware source code being sold?
The LockBit Black used in these attacks was likely built via the LockBit 3.0 builder, which was leaked by a disgruntled developer in September 2022. However, this campaign is not believed to have any connection to the actual LockBit ransomware operation.
Phishing emails sent via the Phorpiex botnet contain the subject lines “your document” and “photo of you???” and are sent under the aliases “Jenny Brown” or “Jenny Green” from more than 1,500 unique IP addresses worldwide, including Kazakhstan, Uzbekistan, Iran, Russia, and China.
The attack chain begins when the recipient opens the malicious ZIP attachment and executes the binary. This executable downloads a LockBit Black ransomware sample from the Phorphiex botnet infrastructure and executes it on the system . Once launched, it will attempt to steal sensitive data, terminate services, and encrypt files.
See also: LockBit ransomware: Claimed responsibility for cyberattack on the city of Wichita
Cybersecurity firm Proofpoint, which is investigating these attacks, said the attackers are targeting companies in various industries worldwide.
Such attacks are extremely common, but this campaign stands out due to the huge number of emails sent to deliver the LockBit Black ransomware.
“Beginning on April 24, 2024 and continuing daily for approximately a week, Proofpoint observed high-volume campaigns with millions of messages facilitated by the Phorpiex botnet and delivering the LockBit Black ransomware,” Proofpoint researchers said.
See also: Dmitry Yuryevich Khoroshev: Identity of LockBit ransomware administrator revealed

Phishing protection
- User education is crucial. Users need to be informed about phishing techniques and how to recognize suspicious messages or links.
- Use phishing detection technologies. There are tools and services that can detect and block phishing attacks before they reach the end user.
- Implement multi-factor authentication policies. This can include using one-time passwords, SMS , or using authentication apps.
- Keep software and systems up to date. Software updates often include security fixes that can protect against attacks .
- Regularly check your logs and security reports to detect potential phishing attacks. Prevention is important, but knowing how and when a user was attacked can help prevent future attacks.
Source: www.bleepingcomputer.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
