Ransomware Gangs Use LockBit’s Fame to Intimidate Victims in Latest Attacks
Threat actors have abused the Transfer Acceleration feature of Amazon S3 (Simple Storage Service) in ransomware attacks aiming to steal victim data and upload it to S3 buckets.
Researchers Jaromir Horejsi and Nitesh Surana of Trend Micro claimed that attempts were made to pass off the Golang ransomware as the well-known LockBit virus. That isn't the case, though, and the attacker appears to be using LockBit's reputation as leverage to snare its victims further.
In an indication that adversaries are increasingly using well-known cloud service providers as weapons for harmful schemes, it has been discovered that the ransomware artifacts incorporate hard-coded Amazon Web Services (AWS) credentials to enable data exfiltration to the cloud read more about Ransomware Gangs Use LockBit's F...

