ATT&CKReferencesFBI Lockbit 2.0 FEB 2022

FBI Lockbit 2.0 FEB 2022

FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples24

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareStealBit

StealBit can upload data and files to the LockBit victim-shaming site.

T1057
Process Discovery
MalwareLockBit 2.0

LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration.

T1059.001
PowerShell
MalwareLockBit 2.0

LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy.

T1059.003
Windows Command Shell
MalwareLockBit 2.0

LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.

T1070.004
File Deletion
MalwareLockBit 2.0

LockBit 2.0 can delete itself from disk after execution.

T1070.004
File Deletion
MalwareStealBit

StealBit can self-delete its executable file from the compromised system.

T1071.001
Web Protocols
MalwareStealBit

StealBit can use HTTP to exfiltrate files to actor-controlled infrastructure.

T1082
System Information Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate system information including hostname and domain information.

T1083
File and Directory Discovery
MalwareStealBit

StealBit can be configured to exfiltrate specific file types.

T1083
File and Directory Discovery
MalwareLockBit 2.0

LockBit 2.0 can exclude files associated with core system functions from encryption.

T1112
Modify Registry
MalwareLockBit 2.0

LockBit 2.0 can create Registry keys to bypass UAC and for persistence.

T1120
Peripheral Device Discovery
MalwareLockBit 2.0

LockBit 2.0 has the ability to identify mounted external storage devices.

T1135
Network Share Discovery
MalwareLockBit 2.0

LockBit 2.0 can discover remote shares.

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 2.0

LockBit 2.0 can decode scripts and strings in loaded modules.

T1140
Deobfuscate/Decode Files or Information
MalwareStealBit

StealBit can deobfuscate loaded modules prior to execution.

T1480
Execution Guardrails
MalwareLockBit 2.0

LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region.

T1484.001
Group Policy Modification
MalwareLockBit 2.0

LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains.

T1490
Inhibit System Recovery
MalwareLockBit 2.0

LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts.

T1547.001
Registry Run Keys / Startup Folder
MalwareLockBit 2.0

LockBit 2.0 can use a Registry Run key to establish persistence at startup.

T1548.002
Bypass User Account Control
MalwareLockBit 2.0

LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`.

T1614.001
System Language Discovery
MalwareLockBit 2.0

LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so.

T1680
Local Storage Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate local drive configuration.

T1685
Disable or Modify Tools
MalwareLockBit 2.0

LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender.

T1685.005
Clear Windows Event Logs
MalwareLockBit 2.0

LockBit 2.0 can delete log files through the use of wevtutil.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.