FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
MalwareLockBit 3.0 | LockBit 3.0 can use SMB for lateral movement. |
| T1027.013 Encrypted/Encoded File |
MalwareLockBit 3.0 | The LockBit 3.0 payload includes an encrypted main component. |
| T1059.001 PowerShell |
MalwareLockBit 3.0 | LockBit 3.0 can use PowerShell to apply Group Policy changes. |
| T1070.004 File Deletion |
MalwareLockBit 3.0 | LockBit 3.0 can delete itself from disk. |
| T1071.001 Web Protocols |
MalwareLockBit 3.0 | LockBit 3.0 can use HTTP to send victim host information to C2. |
| T1078.003 Local Accounts |
MalwareLockBit 3.0 | LockBit 3.0 can use a compromised local account for lateral movement. |
| T1082 System Information Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can enumerate system hostname and domain. |
| T1083 File and Directory Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can exclude files associated with core system functions from encryption. |
| T1112 Modify Registry |
MalwareLockBit 3.0 | LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender. |
| T1120 Peripheral Device Discovery |
MalwareLockBit 3.0 | LockBit 3.0 has the ability to discover external storage devices. |
| T1132.001 Standard Encoding |
MalwareLockBit 3.0 | LockBit 3.0 can Base64-encode C2 communication. |
| T1135 Network Share Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify network shares on compromised systems. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 3.0 | The LockBit 3.0 payload is decrypted at runtime. |
| T1480 Execution Guardrails |
MalwareLockBit 3.0 | LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list. |
| T1480.002 Mutual Exclusion |
MalwareLockBit 3.0 | LockBit 3.0 can create and check for a mutex containing a hash of the `MachineGUID` value at execution to prevent running more than one instance. |
| T1484.001 Group Policy Modification |
MalwareLockBit 3.0 | LockBit 3.0 can enable options for propogation through Group Policy Objects. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms. |
| T1489 Service Stop |
MalwareLockBit 3.0 | LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption. |
| T1490 Inhibit System Recovery |
MalwareLockBit 3.0 | LockBit 3.0 can delete volume shadow copies. |
| T1547.004 Winlogon Helper DLL |
MalwareLockBit 3.0 | LockBit 3.0 can enable automatic logon through the `SOFTWARE\Microsoft\Windows |
| T1548.002 Bypass User Account Control |
MalwareLockBit 3.0 | LockBit 3.0 can bypass UAC to execute code with elevated privileges through an elevated Component Object Model (COM) interface. |
| T1573.001 Symmetric Cryptography |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt C2 communications with AES. |
| T1614.001 System Language Discovery |
MalwareLockBit 3.0 | LockBit 3.0 will not affect machines with language settings matching a defined exlusion list of mainly Eastern European languages. |
| T1680 Local Storage Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can enumerate local drive configuration. |
| T1685 Disable or Modify Tools |
MalwareLockBit 3.0 | LockBit 3.0 can disable security tools to evade detection including Windows Defender. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 3.0 | LockBit 3.0 can delete log files on targeted systems. |
| T1688 Safe Mode Boot |
MalwareLockBit 3.0 | LockBit 3.0 can reboot the infected host into Safe Mode. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.