ZeroFox Intelligence Brief - Ransomware & Digital Extortion - LockBit Targeting
|by Alpha Team

ZeroFox Intelligence Brief - Ransomware & Digital Extortion - LockBit Targeting
Product Serial: B-2023-11-17a
TLP:CLEAR
In this Intelligence Brief, ZeroFox researchers provide an overview of the LockBit ransomware strain, including its targeting, intrusion vectors, and initial access brokers, based on its primary role in ransomware and digital extortion.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Key Findings
- LockBit has been the primary ransomware and digital extortion (R&DE) threat to almost all industries in all locations.
- While LockBit will very likely remain one of the greatest R&DE threats, the proportion of total attacks that LockBit accounts for is on a downward trajectory.
- Diversification of the R&DE threat landscape is being driven by new threat collectives demonstrating proficiency at pace and prolific LockBit affiliates likely choosing to instead deploy other strains or create their own.
- While the LockBit threat will very likely remain high, security teams should monitor for an increasingly diverse spectrum of R&DE operations.
Tags: tlp:clear, threat actor, DDW Ransomware