HomeSecurityRansomware gangs use LockBit's notoriety to pressure victims

Ransomware gangs use LockBit's fame to pressure victims

Hackers are abusing the Transfer Acceleration feature of Amazon S3 (Simple Storage Service) in ransomware attacks designed to steal victims' data and upload it to S3 buckets under their control. In fact, according to researchers at Trend Micro, the attackers have attempted to present the attacks as attacks by the LockBit ransomware.

Ransomware LockBit

Attempts were made to disguise the Golang ransomware as the infamous LockBit ransomware,” researchers Jaromir Horejsi and Nitesh Surana. “However, this is not the case and the attacker appears to be only exploiting the reputation of LockBit to further pressure its victims.”

See also: Bug in Mallox Ransomware allows victims to recover files without paying ransom

Researchers have observed that the attacks incorporate hard-coded Amazon Web Services (AWS) credentials to facilitate data extraction to the cloud. The AWS account used in the campaign could be either the attackers’ own or a compromised account. Following a responsible disclosure to the AWS security team, the AWS access keys and accounts have been suspended.

Trend Micro said it detected more than 30 samples with AWS Access Key IDs and Secret Access Keys embedded. The ransomware is capable of targeting Windows and macOS systems.

We don't know exactly how the ransomware is delivered to the target, but once executed, it obtains the universal unique identifier (UUID) and performs a series of steps to generate the master key required to encrypt the files.

Attackers control root directories and the ransomware encrypts files with specific extensions, after first stealing them and transferring them to AWS via S3 Transfer Acceleration.

See also: Healthcare ransomware attacks are putting lives at risk

After encryption, the file is renamed and takes the following format: <original file name>.<initialization vector>.abcd», the researchers said.

In the final stage, the ransomware changes the device's wallpaper to display an image that mentions LockBit 2.0.

Researchers believe that using the name LockBit may be effective, as it is a well-known ransomware that can terrify victims, thus putting them under more pressure to pay the ransom.

Amazon S3

Ransomware protection

Back up your data: One of the most effective ways to protect yourself from a  attack  is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.

Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest  security  and software updates to prevent any vulnerabilities that could be exploited by ransomware.

Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Crypt Ghouls targets Russian businesses with LockBit 3.0 and Babuk ransomware

Use antivirus software:  Installing reputable antivirus software on your devices can help you detect and prevent attacks  . Be sure to update your antivirus software to ensure it is equipped to handle new threats.

Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.

Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.

Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to attacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS