ATT&CKReferencesSentinelOne LockBit 2.0

SentinelOne LockBit 2.0

SentinelOne. (n.d.). LockBit 2.0: In-Depth Analysis, Detection, Mitigation, and Removal. Retrieved January 24, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareLockBit 2.0

LockBit 2.0 has the ability to move laterally via SMB.

T1057
Process Discovery
MalwareLockBit 2.0

LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration.

T1486
Data Encrypted for Impact
MalwareLockBit 2.0

LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data.

T1489
Service Stop
MalwareLockBit 2.0

LockBit 2.0 can automatically terminate processes that may interfere with the encryption or file extraction processes.

T1685.005
Clear Windows Event Logs
MalwareLockBit 2.0

LockBit 2.0 can delete log files through the use of wevtutil.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.