ATT&CKReferencesCybereason Lockbit 2.0

Cybereason Lockbit 2.0

Cybereason Global SOC Team. (n.d.). THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom. Retrieved January 24, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
MalwareLockBit 2.0

LockBit 2.0 can use wmic.exe to delete volume shadow copies.

T1059.003
Windows Command Shell
MalwareLockBit 2.0

LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.

T1070.004
File Deletion
MalwareLockBit 2.0

LockBit 2.0 can delete itself from disk after execution.

T1490
Inhibit System Recovery
MalwareLockBit 2.0

LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts.

T1685.005
Clear Windows Event Logs
MalwareLockBit 2.0

LockBit 2.0 can delete log files through the use of wevtutil.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.