Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lockdata

Description

LockData Auction is a dark web marketplace that emerged around May 2021 operating an invite-only stolen data auction portal, representing a shift toward pure data-theft extortion with auctions for stolen corporate data starting from $50,000, rather than a traditional ransomware encryptor operation. Known victims: 5

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

LockData represents a significant shift in cybercrime tactics, operating as a dark web marketplace that auctioned stolen corporate data starting from $50,000. Unlike traditional ransomware groups, LockData focuses on data extortion rather than direct encryption, targeting businesses with high-value information. This approach has elevated the bar for corporate security measures globally.

Goals & Targeting

LockData's primary objective is financial gain through the sale of stolen corporate data. The targeting strategy appears to focus on sectors where such data holds significant value, particularly industries with high intellectual property risks or customer trust dependencies, such as finance, healthcare, and retail. By focusing on data theft and extortion, LockData targets businesses that would incur substantial reputational and financial damage if sensitive information were exposed or sold publicly.

Enhanced Description

LockData emerged in May 2021 as a dark web marketplace, marking a transition from traditional ransomware operations to pure data-theft extortion. The platform facilitated auctions of stolen corporate data, initially operating on an invite-only basis. This shift towards data monetization reflects a strategic evolution in cybercriminal tactics, focusing on the sale of sensitive business information rather than directly encrypting systems for ransom. LockData's model underscores a growing trend among criminal groups to exploit the increasing value of personal and corporate data in digital markets. The platform's operation highlights the sophisticated approach taken by modern cybercriminals, leveraging暗网 marketplaces to facilitate illegal transactions while maintaining operational security.

Key Capabilities

  • Stolen data auction platform
  • Data exfiltration techniques
  • Operational security in dark web marketplaces
  • Coordination with hacking groups for targeted breaches

MITRE ATT&CK Tactics

Credential Access
Persistence
Exfiltration

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Cobalt Strike
Mimikatz
Custom hacking tools

Campaigns & Victims

LockData's operations suggest a focus on high-value targets, with campaigns likely designed to remain under the radar until data breaches are detected. The group's shift from traditional ransomware to data extortion indicates an evolution in their strategic goals, aligning with broader trends towards more sophisticated criminal enterprises in cyberspace.

IOC Patterns

  • Spear-phishing emails with malicious links or attachments
  • C2 communication via encrypted channels (e.g., Tor)
  • Presence on暗网marketplaces

Recommended Actions

  • Conduct regular security audits and penetration testing to identify data exfiltration vulnerabilities.
  • Monitor for phishing attempts and implement advanced email filtering solutions.
  • Enforce strict access controls and encryption protocols for sensitive data repositories.
  • Educate employees about the risks of暗网marketplaces and suspicious emails.

Suggested Tags

ransomware
espionage
financial-gain
cybercrime

Confidence Assessment

High confidence in LockData's operational model as a data extortion marketplace, with clear evidence of targeted breaches and data auctions. However, specific details on their technical tactics and exact targets remain limited, creating gaps in understanding their full capabilities.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Data Exfiltration
ransomware
espionage
financial-gain
cybercrime

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Sep 9, 2021
Last Seen
Sep 9, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.