EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Threat actor database
Threat actor profile

LockBit 3.0

Defensive profile aggregated solely from the catalogued evidence. Associations reflect the sources and are not independent EudorIA attribution.

Evidence status
observed
First observation
Not available
Last observation
21/11/2023
Correlated signals
2
Observed picture

What the sources describe

Cybersecurity Advisory #StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability Release Date November 21, 2023 Alert Code AA23-325A Related topics: Cyber Threats and Response , Multifactor Authentication , Cybersecurity Best Practices SUMMARY Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing & Analysis Center (MS-ISAC), and Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) are releasing this joint Cybersecurity Advisory (CSA) to disseminate IOCs, TTPs, and detection methods associated with LockBit 3.0 ransomware exploiting CVE-2023-4966, labeled Citrix Bleed, affecting Citrix NetScaler web application delivery control (ADC) and NetScaler Gateway appliances. This CSA provides TTPs and IOCs obtained from FBI, ACSC, and voluntarily shared by Boeing. Boeing observed LockBit 3.0 affiliates exploiting CVE-2023-4966, to obtain initial access to Boeing Distribution Inc., its parts and distribution business that maintains a separate environment. Other trusted third parties have observed similar activity impacting their organization. Historically, LockBit 3.0 affiliates have conducted attacks a

Cybersecurity Advisory #StopRansomware: LockBit 3.0 Release Date March 16, 2023 Alert Code AA23-075A Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response Actions to take today to mitigate cyber threats from ransomware: Prioritize remediating known exploited vulnerabilities. Train users to recognize and report phishing attempts. Enable and enforce phishing-resistant multifactor authentication. SUMMARY Note: this joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing & Analysis Center (MS-ISAC) are releasing this joint CSA to disseminate known LockBit 3.0 ransomware IOCs and TTPs identified through FBI investigations as recently as March 2023. The LockBit 3.0 ransomware operations function as a Ransomware-as-a-Service (RaaS) model and is a continuation of previous versions of the ransomware, LockBit 2.0, and LockBit. Since January 2020, LockBit has functioned as an affiliate-based ransomware variant; affiliates deploying the LockBit RaaS use many varying TTPs and attack a wide range of businesses and critical infrastructure organizations, which can make effective computer network defense and mitigation challenging. The FBI, CISA, and the MS-IS

AliasesNot catalogued
RansomwareNot documented
MalwareNot documented
Named targetsUS
Modus operandi

Observed methods and techniques

0 structured pieces of evidence
T1082T1539T1556.006T1563T1003.001T1021.001T1027T1046T1048T1070.004T1071.002T1072T1078T1133T1189T1190T1480.001T1485T1486T1489T1490T1491.001T1547T1566T1567T1567.002T1572T1614.001
Risk reduction

How to prepare the defence

Controls linked to the evidence

The sources contain no explicit defensive guidance. The services below are deterministically correlated to the catalogued TTPs, not generated as claims about the actor.

EudorIA

Security Assessment

Verifica esposizione, configurazioni e priorita di remediation prima che una tecnica osservata diventi un incidente.

Approfondisci il servizio →
EudorIA

Managed WAF

Protegge applicazioni e API esposte con regole gestite, virtual patching e analisi degli eventi applicativi.

Approfondisci il servizio →
EudorIA

Identity Security Managed

Riduce abuso di credenziali e accessi anomali con MFA, controllo delle identita e verifica continua.

Approfondisci il servizio →
EudorIA

Backup e continuita operativa

Prepara copie isolate, prove di ripristino e procedure operative per limitare l'impatto di cifratura o distruzione.

Approfondisci il servizio →

The measures listed reduce likelihood and impact but do not guarantee the absolute prevention of an attack.

Tor intelligence

Catalogued onion sources

0

No onion source associated with this group.

Evidence trail

Linked observations

Last 2