ATT&CKReferencesINCIBE-CERT LockBit MAR 2024

INCIBE-CERT LockBit MAR 2024

INCIBE-CERT. (2024, March 14). LockBit: response and recovery actions. Retrieved February 5, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareLockBit 3.0

LockBit 3.0 can use code packing to hinder analysis.

T1071.001
Web Protocols
MalwareLockBit 3.0

LockBit 3.0 can use HTTP to send victim host information to C2.

T1106
Native API
MalwareLockBit 3.0

LockBit 3.0 has the ability to directly call native Windows API items during execution.

T1112
Modify Registry
MalwareLockBit 3.0

LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender.

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 3.0

The LockBit 3.0 payload is decrypted at runtime.

T1486
Data Encrypted for Impact
MalwareLockBit 3.0

LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms.

T1489
Service Stop
MalwareLockBit 3.0

LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption.

T1490
Inhibit System Recovery
MalwareLockBit 3.0

LockBit 3.0 can delete volume shadow copies.

T1685
Disable or Modify Tools
MalwareLockBit 3.0

LockBit 3.0 can disable security tools to evade detection including Windows Defender.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.