Tag: LockBit Ransomware

Hackers now use Velociraptor DFIR tool in ransomware attacks
News

Hackers now use Velociraptor DFIR tool in ransomware attacks

The Velociraptor digital forensics and incident response (DFIR) tool has begun to be used by threat actors in assaults that use the Babuk and LockBit ransomware. According to Cisco Talos analysts, there is a medium level of confidence that the campaigns are being carried out by a Chinese adversary known as Storm-2603. Mike Cohen developed the open-source DFIR tool Velociraptor. Rapid7 has acquired the project and offers its clients an improved version. On August 26, the cybersecurity firm Sophos revealed that hackers were abusing Velociraptor to get remote access. In particular, the threat actors used it to create a secure communication tunnel with the command and control (C2) infrastructure by downloading and running Visual Studio Code on compromised systems read more about Hack...
Russian Hacker Dmitry Khoroshev Unmasked as LockBit Ransomware Administrator
News

Russian Hacker Dmitry Khoroshev Unmasked as LockBit Ransomware Administrator

The creator and administrator of the LockBit ransomware operation, Dmitry Yuryevich Khoroshev, a 31-year-old Russian national, has been identified by the U.K. National Crime Agency (NCA). Khoroshev has also received approval from the Australian Department of Foreign Affairs, the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), and the Foreign, Commonwealth and Development Office (FCD) in the United Kingdom. Authorities have approximately 2,500 decryption keys, according to a press release from Europol, and they are still reaching out to LockBit victims to assist. A travel ban and asset freeze have also been imposed on Khoroshev, also known by the aliases LockBitSupp and putinkrab. The U.S. Department of State is offering a reward of up to $10 million for...
U.S. Offers $15 Million Bounty to Hunt Down LockBit Ransomware Leaders
News

U.S. Offers $15 Million Bounty to Hunt Down LockBit Ransomware Leaders

The U.S. State Department has declared cash rewards of up to $15 million for details that may help identify key figures within the LockBit ransomware group and lead to the apprehension of any involved individuals. The State Department highlighted that since January 2020, LockBit perpetrators have carried out over 2,000 assaults on targets within the United States and globally. These attacks have resulted in significant disruptions to operations and the loss or theft of sensitive data. Furthermore, LockBit ransomware incidents have led to ransom payments totaling more than $144 million for recovery purposes. This development coincides with a broad law enforcement investigation spearheaded by the National Crime Agency (NCA) of the United Kingdom (UK) that has crippled LockBit read ...
LockBit Ransomware Exploiting Critical Citrix Bleed Vulnerability to Break In
News

LockBit Ransomware Exploiting Critical Citrix Bleed Vulnerability to Break In

A recently discovered critical security vulnerability in Citrix NetScaler application delivery control (ADC) and Gateway appliances is being actively exploited by a number of threat actors, including affiliates of the LockBit ransomware, in order to gain initial access to target environments. The Australian Signals Directorate's Australian Cyber Security Center (ASD's ACSC), the Federal Bureau of Investigation (FBI), the Multi-State Information Sharing and Analysis Center (MS-ISAC), and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have all contributed to the joint advisory. "Citrix Bleed, known to be leveraged by LockBit 3.0 affiliates, allows threat actors to bypass password requirements and multifactor authentication read more LockBit Ransomware Exploiting Crit...
20 Year Old Russian LockBit Ransomware Affiliate Arrested in Arizona
News

20 Year Old Russian LockBit Ransomware Affiliate Arrested in Arizona

A Russian national was charged by the U.S. Department of Justice (DoJ) on Thursday for allegedly helping to spread the LockBit ransomware to targets in the Americas, Asia, Europe, and Africa. 20-year-old Chechen Republic resident Ruslan Magomedovich Astamirov is charged with carrying out at least five attacks between August 2020 and March 2023. Last month, he was detained in the state of Arizona. The DoJ stated that Astamirov "allegedly participated in a conspiracy with other LockBit ransomware campaign members to commit wire fraud, intentionally damage protected computers read more 20 Year Old Russian LockBit Ransomware Affiliate Arrested in Arizona. Stay one step ahead of cyber threats with ReconBee.com. Explore our comprehensive coverage of recent cyber attacks, cybersecurity ...
LockBit Ransomware Extorts $91 Million from U.S. Companies
News

LockBit Ransomware Extorts $91 Million from U.S. Companies

Since 2020, the threat actors behind the LockBit ransomware-as-a-service (RaaS) scheme have used hundreds of attacks against several U.S. organisations to demand $91 million in ransom payments. The Federal Bureau of Investigation (FBI), the Multi-State Information Sharing and Analysis Centre (MS-ISAC), and other partner authorities from Australia, Canada, France, Germany, New Zealand, and the U.K. jointly released a bulletin stating as much. "The LockBit ransomware-as-a-service (RaaS) attracts affiliates to use LockBit for conducting ransomware attacks, resulting in a large web of unconnected threat actors conducting wildly varying attacks read more LockBit Ransomware Extorts $91 Million from U.S. Companies. Stay one step ahead of cyber threats with ReconBee.com. Explore our com...