#lockbit — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #lockbit, aggregated by home.social.
-
Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
Pulse Link: https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0
Pulse Author: AlienVault
Created: 2026-07-30 09:41:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault
-
Toy Ghouls’ new toy: the GenieLocker ransomware
GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.
Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
Pulse Link: https://otx.alienvault.com/pulse/6a6b1c3ea08dbc663eb8f4c0
Pulse Author: AlienVault
Created: 2026-07-30 09:41:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault
-
𝗛𝘆𝗳𝗹𝗼𝗰𝗸 𝗮𝗻𝗱 𝗡𝗼𝘃𝗮: 𝗔 𝗣𝗿𝗶𝘃𝗮𝘁𝗲 𝗖𝗼𝗻𝘃𝗲𝗿𝘀𝗮𝘁𝗶𝗼𝗻 𝗣𝗿𝗼𝘃𝗶𝗱𝗲𝘀 𝗮 𝗚𝗹𝗶𝗺𝗽𝘀𝗲 𝗶𝗻𝘁𝗼 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗚𝗿𝗼𝘂𝗽 𝗗𝘆𝗻𝗮𝗺𝗶𝗰𝘀
The chat, which took place between July 1 and July 6, 2026, concerns a request to join Nova’s affiliate program and contains a series of statements regarding the Hyflock group, the interlocutor’s role, and his alleged technical expertise.
-
𝗛𝘆𝗳𝗹𝗼𝗰𝗸 𝗮𝗻𝗱 𝗡𝗼𝘃𝗮: 𝗔 𝗣𝗿𝗶𝘃𝗮𝘁𝗲 𝗖𝗼𝗻𝘃𝗲𝗿𝘀𝗮𝘁𝗶𝗼𝗻 𝗣𝗿𝗼𝘃𝗶𝗱𝗲𝘀 𝗮 𝗚𝗹𝗶𝗺𝗽𝘀𝗲 𝗶𝗻𝘁𝗼 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗚𝗿𝗼𝘂𝗽 𝗗𝘆𝗻𝗮𝗺𝗶𝗰𝘀
The chat, which took place between July 1 and July 6, 2026, concerns a request to join Nova’s affiliate program and contains a series of statements regarding the Hyflock group, the interlocutor’s role, and his alleged technical expertise.
-
📰 Ransomware Roundup: LockBit, Akira, and Others Claim Victims Across Multiple Sectors
Ransomware activity surges on July 1st. Groups like LockBit, Akira, and TheGentlemen claim multiple victims in tech, government, and manufacturing across the globe. 🌎 #Ransomware #DataBreach #LockBit #Akira
🌐 cyber[.]netsecops[.]io
-
📰 Ransomware Roundup: LockBit, Akira, and Others Claim Victims Across Multiple Sectors
Ransomware activity surges on July 1st. Groups like LockBit, Akira, and TheGentlemen claim multiple victims in tech, government, and manufacturing across the globe. 🌎 #Ransomware #DataBreach #LockBit #Akira
🌐 cyber[.]netsecops[.]io
-
🔥 رائج
📢 LockBit Ransomware: التهديد الخطير الذي يجب أن تعرفه - CloudSEK
#Lockbit #Ransomware #Cloudsek #GlobalFeed #News #AR
*تم النشر تلقائيًا بواسطة Global Feed Bot*
-
🔥 رائج
📢 LockBit Ransomware: التهديد الخطير الذي يجب أن تعرفه - CloudSEK
#Lockbit #Ransomware #Cloudsek #GlobalFeed #News #AR
*تم النشر تلقائيًا بواسطة Global Feed Bot*
-
LockBit لا تزالُ تُهدّد مؤسساتنا.
🔹 تستخدم مجموعة الفدية تشفيراً سريعاً وبنية اتصالات مشفّرة لتسليم الفدية.
🔹 الثغرات وضعف سياسات إدارة الدخول هي أنظف طرقهم.نصائح سريعة: حدّث البرمجيات، احفظ نسخاً احتياطية منفصلة، وطبّق سياسات وصول صارمة.
-
🔥 رائج
📢 LockBit Ransomware: التهديد الخطير الذي يجب أن تعرفه - CloudSEK
#Lockbit #Ransomware #Cloudsek #GlobalFeed #News #AR
*تم النشر تلقائيًا بواسطة Global Feed Bot*
-
🔒 مجموعة LockBit تستهدف الشركات بأحدث أساليب التشفير وتطالب بفدية بالبيتكوين.
📌 ما يميزها الآن: تحسين مستمر لتقنيات الاختراق وتوسّع الهجمات لتشمل المالية، الرعاية الصحية والبنية التحتية الحيوية.
🔐 نصيحة سريعة: حدّث نسخك الاحتياطية، درّب الموظفين، ولا تدفع الفدية.
#LockBit #أمن_سيبراني #حماية_البيانات #الخصوصية #تقنية_مفتوحة
-
Ransomware: математический аппарат на службе зла
Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.
https://habr.com/ru/companies/pt/articles/1039170/
#ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки
-
🔥 TRENDING
📢 LockBit Ransomware: التهديد الخطير الذي يجب أن تعرفه - CloudSEK
#Lockbit #Ransomware #Cloudsek #GlobalFeed #News #ARABIC
*Automatically posted by Global Feed Bot*
-
🔥 TRENDING
📢 LockBit Ransomware: التهديد الخطير الذي يجب أن تعرفه - CloudSEK
#Lockbit #Ransomware #Cloudsek #GlobalFeed #News #ARABIC
*Automatically posted by Global Feed Bot*
-
Feed: All Latest | Foxconn Ransomware Attack Shows Nothing Is Safe Forever by Lily Hay Newman
AI generated summary, Read the full article for complete information.
Foxconn, the electronics manufacturer best known for building Apple iPhones, recently suffered a ransomware attack by the Nitrogen group, which claims to have stolen 8 TB of data—including schematics and project details for customers such as Dell, Google, Apple, and Nvidia. While Foxconn confirmed that some North American factories experienced a cyber‑attack and are now resuming normal production, it has not verified the attackers’ claims. The breach underscores the growing trend of ransomware groups targeting supply‑chain giants that store both their own and their clients’ intellectual property. Nitrogen, linked to the ALPHV/BlackCat family, listed Foxconn on its breach site; its ransomware is based on “Conti 2” code and suffers a design flaw that prevents decryption even if the attackers wish to restore systems. Foxconn has faced multiple extortion attempts in the past, including high‑profile incidents in 2020, 2022, and 2024, highlighting the persistent risk of large‑scale data theft and disruption across the tech industry.
Read more: https://www.wired.com/story/foxconn-ransomware-attack-shows-nothing-is-safe-forever/
#Foxconn #Nitrogen #Apple #LockBit #security_cyberattacksandhacks #AllanLiska
-
LockBit 5.0 in Escalation: dalla Banca delle Banche Centrali Latinoamericane alle logistiche Europee
LockBit 5.0 (ChuongDong) torna a colpire ad aprile 2026: tra le vittime Bladex, la banca delle banche centrali latinoamericane, e logistiche tedesche. Analisi tecnica del nuovo payload cross-platform con cifratura differenziale, ETW patching e persistenza fileless. -
LockBit 5.0 in Escalation: dalla Banca delle Banche Centrali Latinoamericane alle logistiche Europee
LockBit 5.0 (ChuongDong) torna a colpire ad aprile 2026: tra le vittime Bladex, la banca delle banche centrali latinoamericane, e logistiche tedesche. Analisi tecnica del nuovo payload cross-platform con cifratura differenziale, ETW patching e persistenza fileless. -
#Schuldigitalisierung ohne #Cybersecurity: Ende Januar 2025 griff ein Ableger der #Lockbit-#Ransomware den rheinland-pfälzischen IT-Dienstleister Topackt an und verschlüsselte 45 Server. Über zwei Terabyte hochsensibler Schuldaten von mehr als 40 Schulen landeten schließlich im #Darknet.
Schulen und kommunale Einrichtungen werden von den Bundesländern in Sachen digitaler #Resilienz nach wie vor weitestgehend sich selbst überlassen - sollen aber massiv digitalisieren:
-
#Schuldigitalisierung ohne #Cybersecurity: Ende Januar 2025 griff ein Ableger der #Lockbit-#Ransomware den rheinland-pfälzischen IT-Dienstleister Topackt an und verschlüsselte 45 Server. Über zwei Terabyte hochsensibler Schuldaten von mehr als 40 Schulen landeten schließlich im #Darknet.
Schulen und kommunale Einrichtungen werden von den Bundesländern in Sachen digitaler #Resilienz nach wie vor weitestgehend sich selbst überlassen - sollen aber massiv digitalisieren:
-
Thanks to samples provided by @pinkflawd you can now look at the beauty of #Lockbit's obfuscated control-flow via @cfgbot by @tmr232
RE: https://mastodon.social/@cfgbot/116202847162981925 -
Thanks to samples provided by @pinkflawd you can now look at the beauty of #Lockbit's obfuscated control-flow via @cfgbot by @tmr232
RE: https://mastodon.social/@cfgbot/116202847162981925 -
🇨🇱 LockBit 5.0 has now published all the information from Clínica Dávila (http://davila.cl). Remember that this medical institution was attacked by the Devman ransomware back in December last year. It appears that Devman sold a portion of the data to LockBit.
Now the question that arises: Has Clínica Dávila individually notified each patient about the attack it suffered from Devman back in December last year?
https://www.security-chu.com/2026/03/lockbit-filtra-los-datos-de-la-clinica-davila.html
#cybersecurity #ransomware #Chile #databreach #health #healthcare #lockbit #devman #research
-
🇨🇱 LockBit 5.0 has now published all the information from Clínica Dávila (http://davila.cl). Remember that this medical institution was attacked by the Devman ransomware back in December last year. It appears that Devman sold a portion of the data to LockBit.
Now the question that arises: Has Clínica Dávila individually notified each patient about the attack it suffered from Devman back in December last year?
https://www.security-chu.com/2026/03/lockbit-filtra-los-datos-de-la-clinica-davila.html
#cybersecurity #ransomware #Chile #databreach #health #healthcare #lockbit #devman #research
-
LockBit-Ransomware über Apache-ActiveMQ-Lücke: Angriff in zwei Wellen
Ein ungepatchter Apache-ActiveMQ-Server wurde zum Einfallstor für einen mehrstufigen Ransomware-Angriff, der sich über knapp 19 Tage erstreckte
-
Cyberzbóje w święta nie czekają na serniczka. Kolejna polska spółka ofiarą ransomware?
Zaledwie wczoraj informowaliśmy o potencjalnym kolejnym ataku grupy Safepay, a już dzisiaj trafiła do nas informacja nt. grupy Lockbit 5.0 i prawdopodobnym ataku na polską spółkę – Mosty Katowice Sp. z o.o. Firma to znany lider w branży projektowej i inżynieryjnej w Polsce, działający głównie w budownictwie infrastrukturalnym i usługach...
-
Cyberzbóje w święta nie czekają na serniczka. Kolejna polska spółka ofiarą ransomware?
Zaledwie wczoraj informowaliśmy o potencjalnym kolejnym ataku grupy Safepay, a już dzisiaj trafiła do nas informacja nt. grupy Lockbit 5.0 i prawdopodobnym ataku na polską spółkę – Mosty Katowice Sp. z o.o. Firma to znany lider w branży projektowej i inżynieryjnej w Polsce, działający głównie w budownictwie infrastrukturalnym i usługach...
-
LockBit 5.0 – nowa infrastruktura, publicznie dostępna lista zhakowanych firm i OPSEC grupy pod znakiem zapytania
Nie tak dawno na łamach Sekuraka pisaliśmy o sojuszu grup LockBit, DragonForce oraz Qilin i reaktywacji Lockbit 5.0 z zaawansowanym, wieloplatformowym malwarem, wykorzystującym m.in. silne szyfrowanie. Zgodnie z oceną badaczy z Trend Micro, powrót Lockbit stanowi realne zagrożenie oraz może skutkować zwiększoną częstotliwością ataków, o czym mieliśmy okazję się przekonać...
-
LockBit 5.0 – nowa infrastruktura, publicznie dostępna lista zhakowanych firm i OPSEC grupy pod znakiem zapytania
Nie tak dawno na łamach Sekuraka pisaliśmy o sojuszu grup LockBit, DragonForce oraz Qilin i reaktywacji Lockbit 5.0 z zaawansowanym, wieloplatformowym malwarem, wykorzystującym m.in. silne szyfrowanie. Zgodnie z oceną badaczy z Trend Micro, powrót Lockbit stanowi realne zagrożenie oraz może skutkować zwiększoną częstotliwością ataków, o czym mieliśmy okazję się przekonać...
-
LockBit 5.0: Key IP + Domain Exposed in Rare OPSEC Breakdown
https://www.technadu.com/lockbit-5-0-infrastructure-details-exposed-by-researchers-in-major-security-failure-including-a-key-ip-address-and-domain/615296/Researcher Rakesh Krishnan uncovered and published IP 205.185.116.233 and domain karma0[.]xyz — the backbone of LockBit 5.0’s new leak site. The server runs with open RDP, FTP, HTTP, and other services, exposing glaring vulnerabilities in LockBit’s infrastructure.
A meaningful win for defenders, enabling immediate blocking and further intelligence gathering.
-
OFAC + U.K. + Australia sanction Media Land LLC for providing bulletproof hosting to LockBit, BlackSuit, Play, Evil Corp & Black Basta.
Volosovik (Yalishanda), Zatolokin & Pankova named, along with ML Cloud, MLT & DC Kirishi.Follow @technadu for continuous threat intel.
#CybersecurityNews #Ransomware #LockBit #ThreatIntel -
OFAC + U.K. + Australia sanction Media Land LLC for providing bulletproof hosting to LockBit, BlackSuit, Play, Evil Corp & Black Basta.
Volosovik (Yalishanda), Zatolokin & Pankova named, along with ML Cloud, MLT & DC Kirishi.Follow @technadu for continuous threat intel.
#CybersecurityNews #Ransomware #LockBit #ThreatIntel -
UK Exposes Bulletproof Hosting Operator Linked to LockBit and Evil Corp https://hackread.com/uk-bulletproof-hosting-operator-lockbit-evil-corp/ #Cybersecurity #Bulletproof #CyberCrime #Ransomware #EvilCorp #FiveEyes #Hosting #LockBit #Russia #NCA
-
UK Exposes Bulletproof Hosting Operator Linked to LockBit and Evil Corp https://hackread.com/uk-bulletproof-hosting-operator-lockbit-evil-corp/ #Cybersecurity #Bulletproof #CyberCrime #Ransomware #EvilCorp #FiveEyes #Hosting #LockBit #Russia #NCA
-
NEW - 🚨 The UK National Crime Agency (#NCA) has exposed and sanctioned Alexander Volosovik, aka “Yalishanda,” for running Russian bulletproof hosting operations linked to LockBit, Evil Corp and BlackBasta ransomware.
Read: https://hackread.com/uk-bulletproof-hosting-operator-lockbit-evil-corp/
-
"- 85 active ransomware and extortion groups observed in Q3 2025, reflecting the most decentralized ransomware ecosystem to date.
- 1,590 victims disclosed across 85 leak sites, showing high, sustained activity despite law-enforcement pressure.
- 14 new ransomware brands launched this quarter, proving how quickly affiliates reconstitute after takedowns.
- LockBit's reappearance with version 5.0 signals potential re-centralization after months of fragmentation."
https://thehackernews.com/2025/11/ransomwares-fragmentation-reaches.html
-
Gemäß einer Analyse von Check Point Research weise das dritte Quartal 2025 das bislang dezentralisierteste Ransomware‑Ökosystem auf. Die Untersuchung habe 85 aktive Ransomware‑ und Erpressungsgruppen sowie 1 590 Opfer ergeben, die über 85 Leak‑Seiten publik gemacht worden seien. Und: LockBit mit Version 5.0 ist zurück, woraus ein neuer Trend zur Zentralisierung abgeleitet werden könnte.
https://maniabel.work/archiv/232
#Ransomware #Lockbit #infosec #infosecnews #BeDiS -
Imagine someone selling hacked access like real estate—unwitting gateways to ransomware attacks worth millions. The Volkov case lifts the veil on this shadowy cyber trade. Curious how it all unfolds?
#initialaccessbroker
#ransomware
#cybercrime
#volkovcase
#yanluowang
#lockbit
#cryptocurrency
#cybersecuritytrends
#lawenforcement -
Защита от шифровальщиков. Как происходят атаки и что делать?
За последний год даже те, кто не связан с информационной безопасностью или ИТ-администрированием, узнали о хакерских атаках, в ходе которых уничтожаются или шифруются данные. Теоретически, массовая атака программ-вымогателей может временно парализовать важную инфраструктуру: остановить транспорт, лишить магазины, аптеки и АЗС возможности обслуживать клиентов. Хотя такая картина кажется гиперболизированной, она вполне возможна — особенно на фоне недавних событий и произошедших инцидентов. В статье расскажем о масштабах угрозы и о том, как организации могут противостоять атакам программ-вымогателей. На основе реальных расследований поделимся не только техническими деталями, но и практическими рекомендациями, которые помогут снизить риски и вовремя отреагировать на инцидент.
https://habr.com/ru/companies/jetinfosystems/articles/962282/
#кибербезопасность #ransomware #иб #информационная_безопасность #cybersecurity #расследование_инцидентов #soc #phishing #фишинг #lockbit
-
LockBit Returns — and It Already Has Victims
#LockBit
https://blog.checkpoint.com/research/lockbit-returns-and-it-already-has-victims/ -
I like my individualized mail addresses. I just received a phishing mail to update my data with a Swiss payment system (TWINT) - but it was sent to an address I created for a doctor's appointment system (Onedoc).
The message also contains my postal address from the time I created that account. -
Kolejny sojusz przestępczy. Grupy LockBit, DragonForce i Qilin łączą siły
Nie tak dawno pisaliśmy o sojuszu trzech grup cyberprzestępczych, działających pod nazwą Scattered Lapsus$ Hunters, a już na horyzoncie pojawia się kolejne zagrożenie – powrót grupy LockBIt, tym razem we współpracy z DragonForce oraz Qilin. O LockBicie było głośno w 2024 r., kiedy to w ramach międzynarodowej operacji Cronos, udało...
#WBiegu #Awareness #Dragonforce #Lockbit #Qilin #Ransomware #Sojusz
https://sekurak.pl/kolejny-sojusz-przestepczy-grupy-lockbit-dragonforce-i-qilin-lacza-sily/