LockBit Ransomware Returns With More Effective Attacks

August 19, 2021

Cybersecurity researchers at Trend Micro have been recording an increase in LockBit ransomware campaigns since July. This ransomware-as-a-service first appeared in September 2019 and was quite successful.

LockBit authors claim that LockBit 2.0 is one of today’s fastest file-encrypting ransomware variants in ads in underground forums. Those claims have proven interesting to cybercriminals seeking to make money from ransomware.

Trend Micro researchers have observed several LockBit ransomware campaigns in recent weeks, mainly targeting organizations in Chile, the U.K., Italy and Taiwan.

While LockBit remained under the radar for much of this year, it launched a major attack against Accenture’s professional services company.

LockBit also appears to have benefited from the apparent disappearance of ransomware gangs including REvil and Darkside, with affiliates of those groups turning towards LockBit as their pathway to launch fresh ransomware attacks.

Hackers often gain access to networks via compromised Remote Desktop Protocol (RDP) or VPN accounts that have been leaked or stolen. Alternatively, LockBit attacks sometimes attempt to trick insiders into accessing them with legitimate credentials.

LockBit also succeeds by copying the steps of notorious ransomware groups through certain tactics, techniques and procedures (TTPs) during attacks. LockBit, for example, now uses Ryuk’s Wake-on-LAN function and sends packets to wake offline devices to help them move sideways around networks and compromise as many machines as possible.

LockBit also uses a tool that was previously used by Egregor ransomware – printers in the network to print out ransom notes.

Like many of the most notorious ransomware groups, LockBit adds a double extortion element to the attacks by stealing the victim’s data and threatening to release it if the ransom is not paid as soon as a period expires.

For more information, read the original story in ZDNet.

Top Stories

Related Articles

April 17, 2026 Booking.com has confirmed a data breach exposing customer booking details and contact information, prompting warnings about a more...

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time more...

April 1, 2026 Cisco suffered a cyberattack after attackers used stolen credentials from a compromised developer tool to access its more...

March 30, 2026 Google has expanded its “Results about you” tool, allowing users to remove highly sensitive personal data, including more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn