ATT&CKReferencesSentinel Labs LockBit 3.0 JUL 2022

Sentinel Labs LockBit 3.0 JUL 2022

Walter, J. (2022, July 21). LockBit 3.0 Update | Unpicking the Ransomware’s Latest Anti-Analysis and Evasion Techniques. Retrieved February 5, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples11

TechniqueUsed byProcedure example
T1027.002
Software Packing
MalwareLockBit 3.0

LockBit 3.0 can use code packing to hinder analysis.

T1027.013
Encrypted/Encoded File
MalwareLockBit 3.0

The LockBit 3.0 payload includes an encrypted main component.

T1057
Process Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify and terminate specific services.

T1106
Native API
MalwareLockBit 3.0

LockBit 3.0 has the ability to directly call native Windows API items during execution.

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 3.0

The LockBit 3.0 payload is decrypted at runtime.

T1218.003
CMSTP
MalwareLockBit 3.0

LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges.

T1480
Execution Guardrails
MalwareLockBit 3.0

LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list.

T1486
Data Encrypted for Impact
MalwareLockBit 3.0

LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms.

T1489
Service Stop
MalwareLockBit 3.0

LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption.

T1543.003
Windows Service
MalwareLockBit 3.0

LockBit 3.0 can install system services for persistence.

T1622
Debugger Evasion
MalwareLockBit 3.0

LockBit 3.0 can check heap memory parameters for indications of a debugger and stop the flow of events to the attached debugger in order to hinder dynamic analysis.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.