ATT&CKReferencesPalo Alto Lockbit 2.0 JUN 2022

Palo Alto Lockbit 2.0 JUN 2022

Elsad, A. et al. (2022, June 9). LockBit 2.0: How This RaaS Operates and How to Protect Against It. Retrieved January 24, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareLockBit 2.0

LockBit 2.0 has the ability to move laterally via SMB.

T1053.005
Scheduled Task
MalwareLockBit 2.0

LockBit 2.0 can be executed via scheduled task.

T1059.001
PowerShell
MalwareLockBit 2.0

LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy.

T1059.003
Windows Command Shell
MalwareLockBit 2.0

LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.

T1070.004
File Deletion
MalwareLockBit 2.0

LockBit 2.0 can delete itself from disk after execution.

T1082
System Information Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate system information including hostname and domain information.

T1136
Create Account
MalwareLockBit 2.0

LockBit 2.0 has been observed creating accounts for persistence using simple names like "a".

T1140
Deobfuscate/Decode Files or Information
MalwareLockBit 2.0

LockBit 2.0 can decode scripts and strings in loaded modules.

T1480
Execution Guardrails
MalwareLockBit 2.0

LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region.

T1484.001
Group Policy Modification
MalwareLockBit 2.0

LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains.

T1486
Data Encrypted for Impact
MalwareLockBit 2.0

LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data.

T1548.002
Bypass User Account Control
MalwareLockBit 2.0

LockBit 2.0 can bypass UAC through creating the Registry key `HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration`.

T1564.003
Hidden Window
MalwareLockBit 2.0

LockBit 2.0 can execute command line arguments in a hidden window.

T1614.001
System Language Discovery
MalwareLockBit 2.0

LockBit 2.0 can check if a targeted machine is using a set of Eastern European languages and exit without infection if so.

T1680
Local Storage Discovery
MalwareLockBit 2.0

LockBit 2.0 can enumerate local drive configuration.

T1685
Disable or Modify Tools
MalwareLockBit 2.0

LockBit 2.0 can disable firewall rules and anti-malware and monitoring software including Windows Defender.

T1685.005
Clear Windows Event Logs
MalwareLockBit 2.0

LockBit 2.0 can delete log files through the use of wevtutil.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.