ATT&CKReferencesJoint Cybersecurity Advisory LockBit 3.0 MAR 2023

Joint Cybersecurity Advisory LockBit 3.0 MAR 2023

FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples27

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareLockBit 3.0

LockBit 3.0 can use SMB for lateral movement.

T1027.013
Encrypted/Encoded File
MalwareLockBit 3.0

The LockBit 3.0 payload includes an encrypted main component.

T1059.001
PowerShell
MalwareLockBit 3.0

LockBit 3.0 can use PowerShell to apply Group Policy changes.

T1070.004
File Deletion
MalwareLockBit 3.0

LockBit 3.0 can delete itself from disk.

T1071.001
Web Protocols
MalwareLockBit 3.0

LockBit 3.0 can use HTTP to send victim host information to C2.

T1078.003
Local Accounts
MalwareLockBit 3.0

LockBit 3.0 can use a compromised local account for lateral movement.

T1082
System Information Discovery
MalwareLockBit 3.0

LockBit 3.0 can enumerate system hostname and domain.

T1083
File and Directory Discovery
MalwareLockBit 3.0

LockBit 3.0 can exclude files associated with core system functions from encryption.

T1112
Modify Registry
MalwareLockBit 3.0

LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender.

T1120
Peripheral Device Discovery
MalwareLockBit 3.0

LockBit 3.0 has the ability to discover external storage devices.

T1132.001
Standard Encoding
MalwareLockBit 3.0

LockBit 3.0 can Base64-encode C2 communication.

T1135
Network Share Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify network shares on compromised systems.

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 3.0

The LockBit 3.0 payload is decrypted at runtime.

T1480
Execution Guardrails
MalwareLockBit 3.0

LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list.

T1480.002
Mutual Exclusion
MalwareLockBit 3.0

LockBit 3.0 can create and check for a mutex containing a hash of the `MachineGUID` value at execution to prevent running more than one instance.

T1484.001
Group Policy Modification
MalwareLockBit 3.0

LockBit 3.0 can enable options for propogation through Group Policy Objects.

T1486
Data Encrypted for Impact
MalwareLockBit 3.0

LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms.

T1489
Service Stop
MalwareLockBit 3.0

LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption.

T1490
Inhibit System Recovery
MalwareLockBit 3.0

LockBit 3.0 can delete volume shadow copies.

T1547.004
Winlogon Helper DLL
MalwareLockBit 3.0

LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon` Registry key.

T1548.002
Bypass User Account Control
MalwareLockBit 3.0

LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface.

T1573.001
Symmetric Cryptography
MalwareLockBit 3.0

LockBit 3.0 can encrypt C2 communications with AES.

T1614.001
System Language Discovery
MalwareLockBit 3.0

LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages.

T1680
Local Storage Discovery
MalwareLockBit 3.0

LockBit 3.0 can enumerate local drive configuration.

T1685
Disable or Modify Tools
MalwareLockBit 3.0

LockBit 3.0 can disable security tools to evade detection including Windows Defender.

T1685.005
Clear Windows Event Logs
MalwareLockBit 3.0

LockBit 3.0 can delete log files on targeted systems.

T1688
Safe Mode Boot
MalwareLockBit 3.0

LockBit 3.0 can reboot the infected host into Safe Mode.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.