markers = fairyseasom, diviespiao, lotofacil2629, jrkgame, quina6243, lotofacil2631, acompanhantesbelem, stories.info.ig, fhotoacopanhante, galetoshop, pgjogo.com, camwhores.t, laudopronto, airbety, mendyflix, blogdoxerife, topbet51, betncional, ptsavefromnet, madrugagol, quina6018, brasildasorte, tksproductions, xpornium, hentaimam, vunesl, fapello.c, 8tshare6a software download, skysacner, mega2553, lotofacil2978, minhacasamm, inarimanga.con, lotofacil2758, espiao.divi.painel, qxhhb25hbgrvtw9kz, 30446427000189, wetransfernow, snaoinsta, web.conexaoonline.top, lotofacil2708, pgotoacompanhantes, lancenete, krwhatsapp, 8002088080, dbkpop, itamaralimaconcei, emailgodaddy, leenacpr00, luck99.oi, photoacpmpanhantes, esportesnatv, otocinalar, g8hi7tfu7eq, tigrebet, eaglecraft.ru, skykaner, vipshotchat, lotofacil2781, mulherpeladavip, queromaistim, photoacpanhante, camdidiase, lotofacil2897, why is software bixiros.5a8 development process, fotoacompahante, lotofacil2827, lotofacil2778, poderosasbet, lotofacil2756, mobians.ia, localizameo, descontazza, pornocafioca, cldcam, vpdpdc9rvw, photoacompanhantessaopaulo, poplotery, af12bet, pjetrt23, bemegripe, chirssstonerr, eduzztecnologia, wwwrioprevidencia.gov.br.rj, bitexod, 11bet9, mar1717171, 192.168101.1, oornocarioca, jalavanda, lotofacil2820, underhentau, xinymyi, strpchet, fix error fitpukweb software, fitpukweb software, mega2544, lectormto, lotofacil2689, grenbets.io, вуузд, resultado.da.lbr, scannersky, jfemprego, faplello, multcanis, kerolayoficial, d157389anz, biszoxtall software, bolsadeapostas, lotofacil2816, whatsaooweb, www.cod2win.com, erogevn, quina6024, quina6077, vagas.sistemafibra, lotomania2436, imbifashion, software fitpukweb, pixsorte, host20385, fitpukweb software code, should i use moxhit4.6.1 software to write a book, cam4bras, atende.dasa.com.br, lotofacil2787, myreadingmanda, sgi.boticario, 166bet3, wixcombr, 333bet6, vunrsp, legisjet, 43705687000173, reaisbet, why is biszoxtall software free, parceirobv, hdpornocomic, rmovebg, henterogermina, quina6068, onlyfansvazados, jujukwai, lotofacil2730, cate.prefeitura.gov.sp, uuuuúuuuuuuuu, mega2575, bigbets99, imgrinn, jue8888, bestgames.bet, eufrimesa, lotofacil2883, svetapeach, buceflix, lotofacil2810, funaiconcurso, photoacompanhatesbh, how to download biszoxtall software, fairyseadon, otarotnet, deunopostegoias, 8004561237, zoovalhalla, beth365, photoacompanhantessantos, lotofacil2632, lotofacil2702, d4mais, software name moxhit4.6.1, cfop5929, photoacompanahante, barbaramonterotiktok, ragnaplace, bepix365, fairyseasin, disal360, fix zenvekeypo4 software issue, milicianeews2, lotofacil2828, software xastwin36, improve software xastwin36, lotofacil2765, teramisina, slotomanía, déborapeixoto, reelsbet, sidelafila, novonegocios, hexroms, lotofacil2786, ninjalewd, hackerdados, ladye550, photoacompanhantessorocaba, sportingbet365, resultadonba, acompanhantesdenatal, bopromida, problem in zenvekeypo4 software, numero.nubank, sytipchat, cipemarcas, lotofacil2860, lotofacil2805, brazilwasstolen.com, sapioxessual, lilovepdf, xastwin36 software, lotofacil2639, betseep, affect3dstore, software 8tshare6a python, lotofacil2829, megasena2572, lotofacil2826, porcomlegenda, lovecxmen, celergim, alektosped, martinalvr, 5107523000, fullbet365, lotofacil2717, ecosessual, snappinterest, m2004j19l, sssinstagram.con, lotofacil2762, latotolonaclaritza, lelivros.ame, 9uhdmaxv17, lemontorrent, gaymaeltube, moxhit4.6.1 software, cam4bra, betpeed, 0026p20012009il, vittalovitta, motion.dasa.com.br, pixoubet, soankgang, lg27ul500, what is fitpukweb software code, svgpmdf, golaco.bet, gobackto505, vagas.sistemafibra.org.df, sitocalm, mcpipokinnha, stikergl27, lotomania2509, chatrondon, googledrudge, sisgered, lotofacil2780, crwatina, moxhit4.6.1 software testing, papinhochat, lotofacil2782, lotofacil2794, quina6106, lotofacil2729, multicanaiss, receipfy, photoavomp, lotofacil2785, maletubw, fitpukweb software problem, acompanhanteamericana, pornocari9ca, vicpalmar18, quina5967, viviimnd06b, seoquak, lotofacil2899, pornugrafia, ak88888, phtoacompanhantes, quina6049, hackerdados.com, what is 8tshare6a python code, 3037085082, bustvault, error fitpukweb software, photoacomoamhantes, terraesporte, lotofacil2644, 1sotem1, portalpmse, lederliftet, ginocanistem, lotofacil2728, emsonho, why biszoxtall software is needed, jmsun, new software name 8tshare6a, 365yybet, eterogemina, megasena2556, patroasbet, lotofacil2766, trf1rpv, lolitasimps, tecnoticiais, 45437547000197, bradhan8, lotofacil2719, sirsp.caixa, atendedasa, fomnytv, anotherofgirl1, bredham8, cegalexina, testing stonecap3.0.34 software, por.ocarioca, brasilsofts, www.192.168.15.1, pormzog, sophizzxq, fotoacompan, 파주출장마사지, lotofacil2903, gamcpre, superbet88.net, lotomania2442, normohidrose, photoaxomp, nimesulifa, photosacompanha, m.onabet, trembodrolol, amzflix, esportebe, br.com.betano, lotofacil2736, skivoos, 3850er3115r, zenvekeypo4 software problem, spankganb, lotofacil2648, natashateen.com, acompanhantelimeira, photoacom0anhantes, lotofacil2725, zenocoins, lotomañia, lotofacil2779, ava.ceinet, asrrgbled, relacionamento.iluminim, xvideosonlufans, cwbot.tk, gamedoce, bytlink, casasdeapostas.com, barbieslot, pauladadelivros, grennbets, goodpprn, lotofacil2859, tothhub, acompanhantescriciuma, photoaconpanha, 27084120134, 35290637000144, futeboplay, girabixo.com, pix.mhnet, falaai.com.voce, lotofacil2907, mangaforfre, lotofacil2760, cam4brasilfemale, lotofacil2812, baixarseries69, 8tshare6a software, formsmash, falapello, lotofacil2755, atrocidades18fans, gemadoff.com.br, pixlucky, closemelb, estripchati, lotomania2478, jesssttone, 8001350050, brimoprida, mudofut, frutcash, xhansterkive, novibrt, pixbetano, mioflez, cidj00, 888sporting, myrendingmanga, lotofacil2831, zenvekeypo4 software, sashemaletube, oral.mc.pipokinha, photoacomoa, robbysonapp, exames.cdigoias.com.br, flavinid, fuxicoria, xilftem, fotocalltv, goxxxcam, lotofacil2802, can4porno, btnacional, pornoegendado, maracujabet, 777bra, fapello.c9m, vivointernetgratis.com.br, 908774498, bug in stonecap3.0.34 software, multianais, showlub, quina6242, lotofacil2694, luvabet.com, sportsdasorte, ql3095, lotofacil2747, acompanhantesemsãocarlos, lotofacil2690, what is moxhit4.6.1 software about, seguroslasa, snapintsa, divasbet, arenasbet, minecraft1.20.0.20

The Relentless Threat of the LockBit Ransomware Gang

2 years ago
tgadmintechgreat
446

LockBit emerged in late 2019, first calling itself “ABCD ransomware.” Since then it has grown rapidly. The group is a ransomware-as-a-service operation, which means that the core team builds its malware and runs its website, licensing its code to “affiliates” who launch the attacks.

Typically, when ransomware groups successfully attack a business and get money, they share some of the profits with affiliates. In the case of LockBit, Jérôme Segura, Senior Director of Threat Intelligence at Malwarebytes, says the partnership model has been turned on its head. Affiliates receive payment directly from their victims and then pay a commission to the core LockBit team. The framework seems to work well and is reliable for LockBit. “The affiliate model was really well tuned,” says Segura.

Although researchers have repeatedly seen how cybercriminals of all kinds have professionalized and streamlined their operations over the past decade, many well-known and prolific ransomware groups use vivid and unpredictable public images to gain notoriety and intimidate victims. On the contrary, LockBit is known for being relatively consistent, focused, and organized.

“I think they were the most businesslike of all the groups, and that’s one of the reasons for their longevity,” says Brett Callow, threat analyst at antivirus company Emsisoft. “But the fact that they post a lot of victims on their site does not necessarily mean that they are the most prolific ransomware group of all, as some claim. However, they are probably quite content to be described in this way. It’s just good for recruiting new partners.”

However, the group is certainly not all publicity. LockBit appears to be investing in both technical and logistical innovation in an attempt to maximize profits. Peter McKenzie, director of incident response at security firm Sophos, says, for example, that the group has experimented with new methods of pressuring its victims to pay a ransom.

“They have different payment methods,” McKenzie says. “You can pay to delete your data, pay to publish early, pay to renew,” MacKenzie says, adding that LockBit has opened up its payment methods to everyone. This could, at least in theory, lead to a rival company buying the ransomware victim’s data. “From the victim’s point of view, it’s additional pressure on them, which helps get people to pay,” says McKenzie.

Since the debut of LockBit, its creators have spent a lot of time and effort developing their malware. The group has published two big code updates – LockBit 2.0 released mid 2021 and LockBit 3.0 released June 2022. These two versions are also known as LockBit Red and LockBit Black respectively. The researchers say the technical evolution has paralleled changes in how LockBit works with affiliates. Prior to the release of LockBit Black, the group worked with an exclusive group of 25 to 50 partners maximum. However, after the release of 3.0, the gang expanded significantly, making it difficult to keep track of the number of affiliates involved, as well as making it harder for LockBit to control the collective.

Leave a Reply