Elsad, A. et al. (2022, June 9). LockBit 2.0: How This RaaS Operates and How to Protect Against It. Retrieved January 24, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to move laterally via SMB. |
| T1053.005 Scheduled Task |
MalwareLockBit 2.0 | LockBit 2.0 can be executed via scheduled task. |
| T1059.001 PowerShell |
MalwareLockBit 2.0 | LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy. |
| T1059.003 Windows Command Shell |
MalwareLockBit 2.0 | LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective. |
| T1070.004 File Deletion |
MalwareLockBit 2.0 | LockBit 2.0 can delete itself from disk after execution. |
| T1082 System Information Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can enumerate system information including hostname and domain information. |
| T1136 Create Account |
MalwareLockBit 2.0 | LockBit 2.0 has been observed creating accounts for persistence using simple names like "a". |
| T1140 Deobfuscate/Decode Files or Information |
MalwareLockBit 2.0 | LockBit 2.0 can decode scripts and strings in loaded modules. |
| T1480 Execution Guardrails |
MalwareLockBit 2.0 | LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region. |
| T1484.001 Group Policy Modification |
MalwareLockBit 2.0 | LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 2.0 | LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data. |
| T1548.002 Bypass User Account Control |
MalwareLockBit 2.0 | LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`. |
| T1564.003 Hidden Window |
MalwareLockBit 2.0 | LockBit 2.0 can execute command line arguments in a hidden window. |
| T1614.001 System Language Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so. |
| T1680 Local Storage Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can enumerate local drive configuration. |
| T1685 Disable or Modify Tools |
MalwareLockBit 2.0 | LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 2.0 | LockBit 2.0 can delete log files through the use of wevtutil. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.