In the world of IT security, threats are constantly evolving. Among them are malicious programs commonly known as ransomware. Their objective is simple: render IT systems inaccessible by encrypting data and demanding a ransom in return. A particularly concerning player in this field is the Lockbit ransomware, which first appeared in 2019 and continues to evolve rapidly, posing serious challenges to organizations worldwide. This group has gained notoriety for its sophisticated and ruthless ransomware strain, infiltrating IT systems, encrypting vital data and demanding high ransoms, leaving victims facing difficult decisions.

History of Lockbit

The beginnings of LockBit

Lockbit was first detected in September 2019 when cybersecurity researchers noticed an email phishing campaign. Initially known as the “ABCD” ransomware due to the “.abcd virus” file extension used during encryption, the ransomware rapidly developed further. In January 2020, the group began operating as a ransomware-as-a-service (RaaS) and adopted the name LockBit.

Growth and diversification

Since then, LockBit has developed several ransomware product variants for encryption: .abcd, LockBit 1.0, LockBit 2.0, LockBit 3.0 and LockBit Green. Each LockBit variation represents an evolution in encryption speed, designed to prevent a company’s cybersecurity measures from countering an attack.

New variant in 2021: LockBit 2.0

In June 2021, the cybercriminals behind Lockbit launched a new version of their malicious software: LockBit 2.0. This update brought several improvements that heightened the threat posed by Lockbit, including more sophisticated mechanisms to avoid detection, as well as a ” Ransomware as a Service ” business model in which cybercriminals rent out the infrastructure needed to carry out attacks. While this version was not the first of its kind, it illustrates the growing trend of ransomware constantly evolving in order to exploit vulnerabilities and security flaws.

June 2022: the emergence of Lockbit 3.0

LockBit 3.0, launched in late June 2022, continues to improve encryption speed to evade security detection. According to cybersecurity experts, this malware employs anti-analysis tactics, only runs with a password, and uses advanced commands.

This ransomware also stands out for its unprecedented Bug Bounty program, inviting users and security specialists to report flaws in exchange for financial rewards, ranging from $1,000 to $1 million. This initiative aims to encourage the disclosure of vulnerabilities exploitable by LockBit and to suggest potential improvements to the group. LockBit is particularly interested in bugs affecting locking systems, flaws in the Tor network, vulnerabilities in the Tox messaging service, and website bugs.

Lockbit, the dominant ransomware in 2023

According to a Trend Micro report, LockBit has managed to stay at the top of ransomware families since 2022, with 26.09% of all known ransomware attacks attributable to it. This figure underscores the scale and prevalence of this threat in today’s cybersecurity landscape.

This ransomware has stood out for its ability to spread very quickly across networks, striking organizations before their users are even aware. Since then, Lockbit has continued to refine its methods, making detection and mitigation even more difficult for companies.

LockBit ransomware strains observed by ANSSI by year
LockBit ransomware strains observed by ANSSI by year

Methods used by Lockbit

The actors behind these attacks are either full-time members of the collective or affiliates who temporarily join the collective in hopes of immediate financial gain. They use several techniques to infect their victims and spread the payload. These methods include:

1. Email phishing

Phishing campaigns are often used as the initial infection vector for ransomware. Cybercriminals send emails containing malicious attachments or links that, once opened or clicked, can install Lockbit on the victim’s computer. Companies must therefore ensure their employees are trained in good IT security practices to limit the risks.

2. Exploitation of known vulnerabilities

Lockbit can also exploit software or hardware vulnerabilities to infiltrate systems and deploy its payload. To guard against this type of attack, it is essential to regularly apply security patches and ensure that all systems are up to date.

3. RDP (Remote Desktop Protocol) brute force

Cybercriminals can also use brute force attacks to gain remote access to IT systems, notably by exploiting weaknesses in the RDP (Remote Desktop Protocol) protocol. If the attacker succeeds in breaking into this system, they can deploy Lockbit and exfiltrate sensitive data before encrypting the files.

The stages of a LockBit attack

LockBit’s attack process centers around three main stages: initial access, lateral movement and privilege escalation, and deployment of the ransomware payload.

  1. Initial access: LockBit often uses social engineering tactics, such as phishing, to obtain user credentials and gain an initial foothold in an organization’s network.
  2. Lateral movement and privilege escalation: Once initial access is obtained, the attackers seek to extend their reach within the compromised network, locating sensitive data and systems to encrypt.
  3. Deployment of the ransomware payload: After preparing the victim’s network for the attack, they deploy the ransomware to encrypt the victims’ files and data and issue the ransom demand.

Sectors targeted by LockBit

LockBit has attacked a variety of organizations across sectors, including education, finance, healthcare, internet software, and professional services. A 2022 Trend Micro report indicated that 80.5% of LockBit’s victims are small and medium-sized businesses. For all companies, the financial cost and damage to their reputation can sometimes prove fatal.

Over an 18-month period, LockBit established itself as the most frequently detected ransomware, illustrated by several major incidents. In January, Royal Mail, the UK’s leading postal service, was paralyzed by a LockBit attack, disrupting its international shipments.

In June 2023, the LockBit group attacked a supplier of Taiwan Semiconductor Manufacturing Company (TSMC), the world’s largest contract chip manufacturer, gaining access to its confidential data. LockBit demanded a ransom of $70 million from TSMC, threatening to leak the stolen information if it went unpaid. One of their most recent victims is the aerospace group Boeing, attacked in October 2023.

Protecting yourself against the Lockbit ransomware

As with any IT threat, there is no single solution to guard against Lockbit. However, a few good security practices can help reduce the risk of being infected by this type of malicious software:

Updating and securing systems

Make sure to keep your systems up to date by regularly applying security patches and ensuring that all applications are secure. This can help limit the vulnerabilities exploited by cybercriminals to spread Lockbit.

Performing regular backups

To minimize the potential impact of a Lockbit attack on a company, it is crucial to perform regular backups of data and ensure they are properly stored off-site. This way, even if files are encrypted during a ransomware infection, the company will always have access to a backup copy of its data.

Employee training and awareness

Implementing training on IT security and best practices to avoid common phishing traps and other attacks can reduce the risk of Lockbit infection. Since cybersecurity is everyone’s responsibility, it is important for every user to be aware of potential threats and know how to identify them.