LockBit Resurfaces with Version 2.0 Ransomware

The Cybersecurity and Infrastructure Security Agency (CISA) shared that Kaseya's VSA software was used to push a malicious PowerSheII script The VSA software

Like other ransomware-as-a-service (RaaS) operations, LockBit 2.0 looks for affiliates to perform the intrusion and exfiltration on targets.

The gang went on a hiring spree in the wake of DarkSide and REvil both shutting down operations, putting up wallpaper on compromised systems that includes text inviting insiders to help compromise systems, and promising payouts of millions of dollars.

LockBit 2.0 shows influences of and similarities to Ryuk and Egregor, particularly certain notable behaviors.

Ransomware Threat Landscape:

Indicators of Compromise

File Hashes

Sha256 – 0545f842ca2eb77bcac0fd17d6d0a8c607d7dbc8669709f3096e5c1828e1c049

URLs

hxxp://lockbitapt6vx57t3eeqjofwgcglmutr3a35nygvokja5uuccip4ykyd[.]onion
hxxp://lockbitsap2oaqhcun3syvbqt6n5nzt7fqosc6jdlmsfleu3ka4k2did[.]onion
hxxp://lockbitsup4yezcd5enk5unncx3zcy7kw6wllyqmiyhvanjj352jayid[.]onion

TTPs

T1562.001: Impair defenses: disable or modify tools
T1070.001: Indicator removal on host: clear Windows Event Logs
T1041: Exfiltration Over C2 Channel
T1486: Data encrypted for impact
T1489: Service stop
T1490: Inhibit System Recovery

Details of the Operations:

On August 23, 2021, a Russian-speaking tech blog YouTube channel “Russian OSINT” published an interview with the representatives of LockBit uncovering details of their operations

The LockBit 2.0 representative claims their ransomware to have the most advanced technical features allowing it to stand up among its competitors. Stated features include:

They do not attack healthcare and educational institutions, as well as social services and charities. Anything that contributes to the development of human beings and their safety remains untouched.

Metmox's Recommendations and Best practices:

Being aware of LockBit 2.0 capabilities, further developments, and how it is currently recruiting affiliates and insiders, it is advised to be prepared for upgrades and a lot more. Below are a few of Metmox’s recommendations that can help organizations prevent and mitigate the impact of attacks.