Site icon Segurança Informática

LockBit 3.0 ransomware analysis

LockBit has been one of the most popular and dangerous ransomware pieces since 2019. The group behind the threat typically attacks critical infrastructures such as health systems, including hospitals.

 

LockBit 2.0 overview

Looking at the LockBit 2.0 website, more than 850 victims were affected in 2022 by this ransomware, a clear sign of the damage and impact caused by the LockBit operators during their wild campaigns. Criminals claim that they damaged at least 12,125 companies during the LockBit 2.0 version, seen below.

Figure1: Total of compromised companies by LockBit 2.0 version.

 

According to the PaloAlto publication, the USA, Italy, Germany, Canada, and France are the top five most affected countries by LockBit 2.0 campaigns, with criminals causing a huge global impact.

Figure 2: Top 10 impacted countries by LockBit 2.0 (source).

 

LockBit 3.0 release

With the introduction of the new release of LockBit ransomware (version 3.0), significant capabilities were implemented, including a bug bounty program and Zcash payments.

Although there are no official numbers about incidents related to this new version, criminals decided to change in June to the LockBit 3.0, and some victims can be found on the group website.

Figure 3: LockBit 3.0 victims.

 

The ransomware notes are no longer named “Restore-My-Files.txt” but were moved to a new format: [id].README.txt, as presented below.

Figure 4: Ransomware note of LockBit 3.0 version.

 

Also, a new desktop wallpaper is introduced by criminals in this fresh release, as shown in Figure 5.

LockBit 2.0 desktop wallpaper (source)

LockBit 3.0 desktop wallpaper

Figure 5: Differences between LockBit 2.0 and 3.0 desktop wallpaper.

 

Notable capabilities introduced in version 3.0

LockBit 3.0 operators introduced a lot of fresh capabilities in this 3.0 version, including:

 

After executing, LockBit 3.0 tries to disable the Windows Defender to prevent its detection, as mentioned above.

Figure 6: LockBit 3.0 disables Windows Defender during its execution. 

 

Within some features observed, criminals also introduced a bounty program bug. This is the first bug bounty program released by a ransomware group that encourages researchers to submit security reports for rewards ranging between $1,000 and $1 million.

We invite all security researchers and ethical and unethical hackers on the planet to participate in our bug bounty program. The amount of remuneration varies from $1,000 to $1 million.

Figure 7: Bug bounty program offered by LockBit operators.

 

The ransomware gang will also reward “brilliant ideas” to improve its operations. As expected, this bug bounty program differs from traditional and legitimate programs. The available categories are presented below.

 

Figure 8: Bug bounty categories present on the LockBit 3.0 website.

 

The addition of Zcash as a payment option is another of the new features present in this new release. In detail, Zcash is a privacy coin, making it harder to trace and the perfect payment method for illegal purposes.

 

Prevention measures

Although there is no magic formula to stop ransomware in general, we can deliver a set of steps to reduce the risk of an incident of this nature.

 

Finally, be proactive and perform cybersecurity assessments to find and mitigate weaknesses to prevent attacks in the wild, both from external and internal perspectives.

 

 


The article was initially published by Pedro Tavares on resources.infosecinstitute.com.
All rights reserved ® infosecinstitute.com

 

Exit mobile version