Its another LockBit update!...
1. LockBit affiliates are actively exploiting ConnectWise's ScreenConnect critical vulnerability, deploying LockBit ransomware. What they are doing with the data when they steal it, and how they are negotiating with victims, is unclear.
2. Law enforcement released their info on Lockbit's admin, but I'll be honest, it's underwhelming (screenshot below)... The unmasking of the Lockbit subgroup National Hazard Agency admin, Bassterlord, has been far more effective and, to be honest, entertaining.
3. Based on what we can see, LockBit have still not restored any public facing infrastructure, and the longer this continues the better!!
4. We are surprised about the lack of movement among the LockBit affiliates. It appears, from what we can see of the major Russophonic darkweb communities, that despite many of them being quite pissed off, they havent yet indicated movement to a new RaaS. Given most of these folks are ex-Conti, BlackMatter, DarkSide, GandCrab and other long-term ransomware affiliates, they have gone through this process before and might be waiting to see what the fallout is before deciding to move to a new RaaS.
#Cybersecurity #LockBit #YourFirstCall #IncidentResponse