ZeroFox Intelligence Flash Report - LockBit Denies Attack Against Russian Entity
|by Alpha Team

ZeroFox Intelligence Flash Report - LockBit Denies Attack Against Russian Entity
Product Serial: F-2024-01-30b
TLP:CLEAR
In this flash report, ZeroFox researchers report on allegations of a successful attack against a Russia-based organization using the LockBit malware strain, which LockBit has subsequently denied.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On January 22, 2024, threat actor “KonstLiv3” caused outrage in dark web community “RAMP” by claiming to have conducted a successful attack against a Russia-based organization using the LockBit malware strain–a claim that would violate the unwritten rules about using the strain to attack entities in Russia and other CIS (Commonwealth of Independent States) countries.
- On January 26, 2024 LockBit representatives made several posts in the forum, one of which claimed that the attack had been conducted by “Signature”-likely referring to a threat actor pseudonym. This was very likely an attempt to deny involvement, sanctioning or knowledge of the attack.
- It is likely the attack took place, and threat actor KonstLiv3 is in possession of the stolen data. It is likely that a customized version of LockBit malware was leveraged.
- The negative community response to this event is almost certainly indicative of the extremely low tolerance within dark web forums for attacks against victims based in the CIS.
Tags: tlp:clear, dark web, threat actor, DDW Ransomware