Malware.View on attack.mitre.org
LockBit 2.0 is an affiliate-based Ransomware-as-a-Service (RaaS) that has been in use since at least June 2021 as the successor to LockBit Ransomware. LockBit 2.0 has versions capable of infecting Windows and VMware ESXi virtual machines, and has been observed targeting multiple industry verticals globally.
| Technique | Procedure example |
|---|---|
| T1021.002 SMB/Windows Admin Shares |
LockBit 2.0 has the ability to move laterally via SMB. |
| T1047 Windows Management Instrumentation |
LockBit 2.0 can use wmic.exe to delete volume shadow copies. |
| T1053.005 Scheduled Task |
LockBit 2.0 can be executed via scheduled task. |
| T1057 Process Discovery |
LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration. |
| T1059.001 PowerShell |
LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy. |
| T1059.003 Windows Command Shell |
LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective. |
| T1070.004 File Deletion |
LockBit 2.0 can delete itself from disk after execution. |
| T1082 System Information Discovery |
LockBit 2.0 can enumerate system information including hostname and domain information. |
| T1083 File and Directory Discovery |
LockBit 2.0 can exclude files associated with core system functions from encryption. |
| T1112 Modify Registry |
LockBit 2.0 can create Registry keys to bypass UAC and for persistence. |
| T1120 Peripheral Device Discovery |
LockBit 2.0 has the ability to identify mounted external storage devices. |
| T1135 Network Share Discovery |
LockBit 2.0 can discover remote shares. |
| T1136 Create Account |
LockBit 2.0 has been observed creating accounts for persistence using simple names like "a". |
| T1140 Deobfuscate/Decode Files or Information |
LockBit 2.0 can decode scripts and strings in loaded modules. |
| T1480 Execution Guardrails |
LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.