ZeroFox Intelligence Brief - LockBit Targeting of the United Kingdom 2022-2023
|by Alpha Team

ZeroFox Intelligence Brief - LockBit Targeting of the United Kingdom 2022-2023
Product Serial: B-2023-12-01b
TLP:CLEAR
In this Intelligence Brief, ZeroFox researchers outline the threat from LockBit to United Kingdom-based organizations over the last two years.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here.
Executive Summary
LockBit is ransomware used by threat actors to infect and extort victims. The strain, identified as early as September 2019, is run as a ransomware-as-a-service (RaaS) offering with a subscription-based business model involving the selling or leasing of malicious code to multiple, fee-paying affiliates on dark web forums. LockBit 3.0—currently the most prolific extortion operation—has been equipped with worm-like capabilities that enable self-propagation across a compromised network. The strain is renowned for its speed of compromise, leveraging strong cryptography to render thousands of files inaccessible to users within seconds. Backups are removed to prevent file recovery attempts.
Tags: tlp:clear, eu/russia, threat actor