Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lockbit2

Description

LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021, introducing automated domain-wide encryption via Active Directory Group Policy and claiming the fastest encryption speed among ransomware families, accounting for 46% of ransomware breach events in early 2022. Known victims: 1002 5 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

LockBit 2.0 is a highly capable ransomware-as-a-service (RaaS) platform that has been responsible for a significant portion of ransomware breach events in 2022. With its automated domain-wide encryption capabilities, it poses a substantial threat to organizations worldwide. LockBit 2.0's speed and efficiency make it a formidable opponent in the cybersecurity landscape.

Goals & Targeting

LockBit 2.0's primary objective is to achieve financial gain through ransom payments, targeting organizations across various sectors. The actor's targeting profile appears to be opportunistic, with a focus on exploiting vulnerable systems and networks to maximize potential returns. Typical victims of LockBit 2.0 include organizations with insufficient cybersecurity measures in place, as well as those with valuable data or systems that can be leveraged for ransom. By understanding the actor's strategic objectives and targeting profile, organizations can better prepare themselves against LockBit 2.0's ransomware campaigns.

Enhanced Description

LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021. This ransomware family has introduced several significant advancements, including automated domain-wide encryption via Active Directory Group Policy. This capability allows LockBit 2.0 to claim the fastest encryption speed among ransomware families, making it a highly formidable threat. As of early 2022, LockBit 2.0 accounted for 46% of ransomware breach events, demonstrating its widespread impact and success. With over 1002 known victims and multiple ransom notes on file, the scale of LockBit 2.0's operations is substantial.

Key Capabilities

  • Automated domain-wide encryption
  • Active Directory Group Policy exploitation
  • Fast encryption speed
  • Ransomware-as-a-service (RaaS) model
  • Opportunistic targeting

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom ransomware

Campaigns & Victims

LockBit 2.0's campaign patterns involve widespread targeting of organizations across various sectors, with a focus on exploiting vulnerable systems and networks. The actor's operational tempo is characterized by rapid encryption and subsequent ransom demands. Notable past operations include the compromise of numerous organizations, resulting in significant financial losses. LockBit 2.0's ability to adapt and evolve its tactics, techniques, and procedures (TTPs) has contributed to its success, making it essential for organizations to stay vigilant and proactive in their defense against this threat.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Unusual Active Directory Group Policy activity

Recommended Actions

  • Implement robust cybersecurity measures, including regular backups and encryption
  • Conduct regular vulnerability assessments and penetration testing
  • Implement a security awareness training program for employees
  • Monitor for suspicious Active Directory Group Policy activity

Suggested Tags

Ransomware
Criminal
RaaS

Confidence Assessment

The confidence level in the available data is medium to high, given the significant amount of information available on LockBit 2.0's operations and tactics. However, there may be gaps in the data regarding the actor's specific targeting criteria and the full extent of their capabilities. Further research and analysis are necessary to fill these gaps and provide a more comprehensive understanding of the LockBit 2.0 threat.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Criminal
RaaS

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 9, 2021
Last Seen
Jun 28, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.