zerofox logo
Advisories

ZeroFox Intelligence Brief - LockBit Targeting of the United Kingdom 2022-2023

|by Alpha Team

banner image

ZeroFox Intelligence Brief - LockBit Targeting of the United Kingdom 2022-2023

Product Serial: B-2023-12-01b

TLP:CLEAR

In this Intelligence Brief, ZeroFox researchers outline the threat from LockBit to United Kingdom-based organizations over the last two years.

Standing Intelligence Requirements

Deep Dark Web and Criminal Underground DDW

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here.

Executive Summary

LockBit is ransomware used by threat actors to infect and extort victims. The strain, identified as early as September 2019, is run as a ransomware-as-a-service (RaaS) offering with a subscription-based business model involving the selling or leasing of malicious code to multiple, fee-paying affiliates on dark web forums. LockBit 3.0—currently the most prolific extortion operation—has been equipped with worm-like capabilities that enable self-propagation across a compromised network. The strain is renowned for its speed of compromise, leveraging strong cryptography to render thousands of files inaccessible to users within seconds. Backups are removed to prevent file recovery attempts.

Tags: tlp:clear,  eu/russia, threat actor