Cybereason Global SOC Team. (n.d.). THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom. Retrieved January 24, 2025.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1047 Windows Management Instrumentation |
MalwareLockBit 2.0 | LockBit 2.0 can use wmic.exe to delete volume shadow copies. |
| T1059.003 Windows Command Shell |
MalwareLockBit 2.0 | LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective. |
| T1070.004 File Deletion |
MalwareLockBit 2.0 | LockBit 2.0 can delete itself from disk after execution. |
| T1490 Inhibit System Recovery |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts. |
| T1685.005 Clear Windows Event Logs |
MalwareLockBit 2.0 | LockBit 2.0 can delete log files through the use of wevtutil. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.