LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021, introducing automated domain-wide encryption via Active Directory Group Policy and claiming the fastest encryption speed among ransomware families, accounting for 46% of ransomware breach events in early 2022. Known victims: 1002 5 ransom note(s) on file
Objectives
Executive Summary
LockBit 2.0 is a highly capable ransomware-as-a-service (RaaS) platform that has been responsible for a significant portion of ransomware breach events in 2022. With its automated domain-wide encryption capabilities, it poses a substantial threat to organizations worldwide. LockBit 2.0's speed and efficiency make it a formidable opponent in the cybersecurity landscape.
Goals & Targeting
LockBit 2.0's primary objective is to achieve financial gain through ransom payments, targeting organizations across various sectors. The actor's targeting profile appears to be opportunistic, with a focus on exploiting vulnerable systems and networks to maximize potential returns. Typical victims of LockBit 2.0 include organizations with insufficient cybersecurity measures in place, as well as those with valuable data or systems that can be leveraged for ransom. By understanding the actor's strategic objectives and targeting profile, organizations can better prepare themselves against LockBit 2.0's ransomware campaigns.
Enhanced Description
LockBit 2.0 is the second major iteration of the LockBit RaaS platform, launched in mid-2021. This ransomware family has introduced several significant advancements, including automated domain-wide encryption via Active Directory Group Policy. This capability allows LockBit 2.0 to claim the fastest encryption speed among ransomware families, making it a highly formidable threat. As of early 2022, LockBit 2.0 accounted for 46% of ransomware breach events, demonstrating its widespread impact and success. With over 1002 known victims and multiple ransom notes on file, the scale of LockBit 2.0's operations is substantial.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LockBit 2.0's campaign patterns involve widespread targeting of organizations across various sectors, with a focus on exploiting vulnerable systems and networks. The actor's operational tempo is characterized by rapid encryption and subsequent ransom demands. Notable past operations include the compromise of numerous organizations, resulting in significant financial losses. LockBit 2.0's ability to adapt and evolve its tactics, techniques, and procedures (TTPs) has contributed to its success, making it essential for organizations to stay vigilant and proactive in their defense against this threat.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the available data is medium to high, given the significant amount of information available on LockBit 2.0's operations and tactics. However, there may be gaps in the data regarding the actor's specific targeting criteria and the full extent of their capabilities. Further research and analysis are necessary to fill these gaps and provide a more comprehensive understanding of the LockBit 2.0 threat.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics