New Lockbit Attack Lasted for Half a Year

One of the most successful ransomware groups of these days, Lockbit, reportedly committed a cyberattack on the regional governmental agency in the USA. Besides that goes against the “ethical hacking” rules this group tries to follow, the exact event took about 6 months to complete.

Lockbit group – what are they?

Lockbit is considered one of the most successful ransomware gangs in 2021. Having the software with outstanding performance and good coordination between units, it reached a lot of well-protected targets and successfully hacked them. The cybersecurity community knows them for having the fastest encryption module, and the use of elliptic curve encryption. Another notable thing about LockBit is its constant image care. During each interview, the group assures that they always give the decryption key and never attack government-related companies.

After the REvil group shutdown, they quickly consumed the released attack potential. In November 2021, the overall share of the LockBit group in total ransomware attacks on the corporations reached 40%. By the rules of “normal” markets that means a complete monopoly. Fortunately, this group opted for small-but-stable gains, attacking generally small companies and avoiding governmental, infrastructure, and educational institutions. At least, they did so up until uncovering the latest attack case.

LockBit attack lasted for half a year

Obviously, none of the ransomware attacks on corporations happen in one day. Usually, it is a chain of events for taking over the corporate network, stealing data, and encrypting the files. The average duration of cyberattacks is around 1 week. In some cases – when the network is well-protected, or the security system alarms about the attack – it may take a bit longer. But this time, LockBit has likely set up a record – more than 5 months since the initial penetration.

Sophos group specialists shared the report that shows the fraudsters did over a dozen steps. They’ve tested different hacktools, remote-access utilities and various programs for file transferring to the remote machine. The peculiar element of this event is that the first infected computer (so-called “patient zero”) was the domain controller. Usually, such an occasion means that the whole network is compromised. Even if it is not – using the DC crooks can create the administrator accounts on all machines in the network. And they apparently did that – but for some reasons, they decided to idle.

James H. Sterling

James H. Sterling

Environmental Science & Climate Journalist

James Sterling reports on renewable energy developments, climate policy, ecological conservation, and green tech innovations around the globe.

Share this article
Twitter Facebook Pinterest