INCIBE-CERT. (2024, March 14). LockBit: response and recovery actions. Retrieved February 5, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareLockBit 3.0 | LockBit 3.0 can use code packing to hinder analysis. |
| T1071.001 Web Protocols |
MalwareLockBit 3.0 | LockBit 3.0 can use HTTP to send victim host information to C2. |
| T1106 Native API |
MalwareLockBit 3.0 | LockBit 3.0 has the ability to directly call native Windows API items during execution. |
| T1112 Modify Registry |
MalwareLockBit 3.0 | LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 3.0 | The LockBit 3.0 payload is decrypted at runtime. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms. |
| T1489 Service Stop |
MalwareLockBit 3.0 | LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption. |
| T1490 Inhibit System Recovery |
MalwareLockBit 3.0 | LockBit 3.0 can delete volume shadow copies. |
| T1685 Disable or Modify Tools |
MalwareLockBit 3.0 | LockBit 3.0 can disable security tools to evade detection including Windows Defender. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.