Walter, J. (2022, July 21). LockBit 3.0 Update | Unpicking the Ransomware’s Latest Anti-Analysis and Evasion Techniques. Retrieved February 5, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
MalwareLockBit 3.0 | LockBit 3.0 can use code packing to hinder analysis. |
| T1027.013 Encrypted/Encoded File |
MalwareLockBit 3.0 | The LockBit 3.0 payload includes an encrypted main component. |
| T1057 Process Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify and terminate specific services. |
| T1106 Native API |
MalwareLockBit 3.0 | LockBit 3.0 has the ability to directly call native Windows API items during execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 3.0 | The LockBit 3.0 payload is decrypted at runtime. |
| T1218.003 CMSTP |
MalwareLockBit 3.0 | LockBit 3.0 can attempt a CMSTP UAC bypass if it does not have administrative privileges. |
| T1480 Execution Guardrails |
MalwareLockBit 3.0 | LockBit 3.0 can make execution dependent on specific parameters including a unique passphrase and the system language of the targeted host not being found on a set exclusion list. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms. |
| T1489 Service Stop |
MalwareLockBit 3.0 | LockBit 3.0 can terminate targeted processes and services related to security, backup, database management, and other applications that could stop or interfere with encryption. |
| T1543.003 Windows Service |
MalwareLockBit 3.0 | LockBit 3.0 can install system services for persistence. |
| T1622 Debugger Evasion |
MalwareLockBit 3.0 | LockBit 3.0 can check heap memory parameters for indications of a debugger and stop the flow of events to the attached debugger in order to hinder dynamic analysis. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.