home.social

#lockbit — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lockbit, aggregated by home.social.

fetched live
  1. Toy Ghouls’ new toy: the GenieLocker ransomware

    GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

    Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
    Pulse Link: otx.alienvault.com/pulse/6a6b1
    Pulse Author: AlienVault
    Created: 2026-07-30 09:41:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault

  2. Toy Ghouls’ new toy: the GenieLocker ransomware

    GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec.

    Pulse ID: 6a6b1c3ea08dbc663eb8f4c0
    Pulse Link: otx.alienvault.com/pulse/6a6b1
    Pulse Author: AlienVault
    Created: 2026-07-30 09:41:18

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #ELF #Encryption #InfoSec #Linux #LockBit #Manufacturing #OTX #OpenThreatExchange #PsExec #RAT #RansomWare #Russia #Rust #SSH #UK #VPN #Windows #bot #AlienVault

  3. 𝗛𝘆𝗳𝗹𝗼𝗰𝗸 𝗮𝗻𝗱 𝗡𝗼𝘃𝗮: 𝗔 𝗣𝗿𝗶𝘃𝗮𝘁𝗲 𝗖𝗼𝗻𝘃𝗲𝗿𝘀𝗮𝘁𝗶𝗼𝗻 𝗣𝗿𝗼𝘃𝗶𝗱𝗲𝘀 𝗮 𝗚𝗹𝗶𝗺𝗽𝘀𝗲 𝗶𝗻𝘁𝗼 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗚𝗿𝗼𝘂𝗽 𝗗𝘆𝗻𝗮𝗺𝗶𝗰𝘀

    The chat, which took place between July 1 and July 6, 2026, concerns a request to join Nova’s affiliate program and contains a series of statements regarding the Hyflock group, the interlocutor’s role, and his alleged technical expertise.

    suspectfile.com/hyflock-and-no

    #Hyflock #LockBit #Nova #Qilin #RaaS #Ransomware

  4. 𝗛𝘆𝗳𝗹𝗼𝗰𝗸 𝗮𝗻𝗱 𝗡𝗼𝘃𝗮: 𝗔 𝗣𝗿𝗶𝘃𝗮𝘁𝗲 𝗖𝗼𝗻𝘃𝗲𝗿𝘀𝗮𝘁𝗶𝗼𝗻 𝗣𝗿𝗼𝘃𝗶𝗱𝗲𝘀 𝗮 𝗚𝗹𝗶𝗺𝗽𝘀𝗲 𝗶𝗻𝘁𝗼 𝗥𝗮𝗻𝘀𝗼𝗺𝘄𝗮𝗿𝗲 𝗚𝗿𝗼𝘂𝗽 𝗗𝘆𝗻𝗮𝗺𝗶𝗰𝘀

    The chat, which took place between July 1 and July 6, 2026, concerns a request to join Nova’s affiliate program and contains a series of statements regarding the Hyflock group, the interlocutor’s role, and his alleged technical expertise.

    suspectfile.com/hyflock-and-no

    #Hyflock #LockBit #Nova #Qilin #RaaS #Ransomware

  5. 📰 Ransomware Roundup: LockBit, Akira, and Others Claim Victims Across Multiple Sectors

    Ransomware activity surges on July 1st. Groups like LockBit, Akira, and TheGentlemen claim multiple victims in tech, government, and manufacturing across the globe. 🌎 #Ransomware #DataBreach #LockBit #Akira

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/br

  6. 📰 Ransomware Roundup: LockBit, Akira, and Others Claim Victims Across Multiple Sectors

    Ransomware activity surges on July 1st. Groups like LockBit, Akira, and TheGentlemen claim multiple victims in tech, government, and manufacturing across the globe. 🌎 #Ransomware #DataBreach #LockBit #Akira

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/br

  7. LockBit لا تزالُ تُهدّد مؤسساتنا.
    🔹 تستخدم مجموعة الفدية تشفيراً سريعاً وبنية اتصالات مشفّرة لتسليم الفدية.
    🔹 الثغرات وضعف سياسات إدارة الدخول هي أنظف طرقهم.

    نصائح سريعة: حدّث البرمجيات، احفظ نسخاً احتياطية منفصلة، وطبّق سياسات وصول صارمة.

    #LockBit #Ransomware #CyberSecurity #حماية #تحديث_البرمجيات

    🔗 news.google.com/rss/articles/C

  8. 🔒 مجموعة LockBit تستهدف الشركات بأحدث أساليب التشفير وتطالب بفدية بالبيتكوين.

    📌 ما يميزها الآن: تحسين مستمر لتقنيات الاختراق وتوسّع الهجمات لتشمل المالية، الرعاية الصحية والبنية التحتية الحيوية.

    🔐 نصيحة سريعة: حدّث نسخك الاحتياطية، درّب الموظفين، ولا تدفع الفدية.

    #LockBit #أمن_سيبراني #حماية_البيانات #الخصوصية #تقنية_مفتوحة

    🔗 news.google.com/rss/articles/C

  9. Ransomware: математический аппарат на службе зла

    Привет, Хабр! Я Илья Борисов, старший специалист отдела экспертизы MaxPatrol EDR антивирусной лаборатории Positive Technologies. В 2025 году команда аналитиков антивирусной лаборатории PT ESC провела исследование актуальных семейств ransomware (aka шифровальщиков), чтобы повысить эффективность их обнаружения нашим продуктом. Этот вид ВПО оказался одной из наиболее значимых и заметных разновидностей вредоносов, используемых в атаках в 2025 году. Мы проанализировали образцы, замеченные в период с конца 2024 года по конец 2025-го. Были разобраны как давно известные семейства шифровальщиков, такие как Black Basta, MedusaLocker и LockBit, и относительно недавно появившиеся Lynx, HellCat и BERT. В этой статье хочу поделиться результатами этого исследования. Для начала расскажу про типы шифровальщиков, на кого они нацелены, как работают, подсвечу технические детали, а также ретроспективно прослежу некоторые тенденции в эволюции ransomware.

    habr.com/ru/companies/pt/artic

    #ransomware #шифровальщики #вредоносное_по #lockbit #blackbasta #ransom #вымогательство #выкуп #кибератаки

  10. Feed: All Latest | Foxconn Ransomware Attack Shows Nothing Is Safe Forever by Lily Hay Newman

    AI generated summary, Read the full article for complete information.

    Foxconn, the electronics manufacturer best known for building Apple iPhones, recently suffered a ransomware attack by the Nitrogen group, which claims to have stolen 8 TB of data—including schematics and project details for customers such as Dell, Google, Apple, and Nvidia. While Foxconn confirmed that some North American factories experienced a cyber‑attack and are now resuming normal production, it has not verified the attackers’ claims. The breach underscores the growing trend of ransomware groups targeting supply‑chain giants that store both their own and their clients’ intellectual property. Nitrogen, linked to the ALPHV/BlackCat family, listed Foxconn on its breach site; its ransomware is based on “Conti 2” code and suffers a design flaw that prevents decryption even if the attackers wish to restore systems. Foxconn has faced multiple extortion attempts in the past, including high‑profile incidents in 2020, 2022, and 2024, highlighting the persistent risk of large‑scale data theft and disruption across the tech industry.

    Read more: wired.com/story/foxconn-ransom

    #Foxconn #Nitrogen #Apple #LockBit #security_cyberattacksandhacks #AllanLiska

  11. LockBit 5.0 in Escalation: dalla Banca delle Banche Centrali Latinoamericane alle logistiche Europee

    LockBit 5.0 (ChuongDong) torna a colpire ad aprile 2026: tra le vittime Bladex, la banca delle banche centrali latinoamericane, e logistiche tedesche. Analisi tecnica del nuovo payload cross-platform con cifratura differenziale, ETW patching e persistenza fileless.

    insicurezzadigitale.com/lockbi

  12. LockBit 5.0 in Escalation: dalla Banca delle Banche Centrali Latinoamericane alle logistiche Europee

    LockBit 5.0 (ChuongDong) torna a colpire ad aprile 2026: tra le vittime Bladex, la banca delle banche centrali latinoamericane, e logistiche tedesche. Analisi tecnica del nuovo payload cross-platform con cifratura differenziale, ETW patching e persistenza fileless.

    insicurezzadigitale.com/lockbi

  13. #Schuldigitalisierung ohne #Cybersecurity: Ende Januar 2025 griff ein Ableger der #Lockbit-#Ransomware den rheinland-pfälzischen IT-Dienstleister Topackt an und verschlüsselte 45 Server. Über zwei Terabyte hochsensibler Schuldaten von mehr als 40 Schulen landeten schließlich im #Darknet.

    Schulen und kommunale Einrichtungen werden von den Bundesländern in Sachen digitaler #Resilienz nach wie vor weitestgehend sich selbst überlassen - sollen aber massiv digitalisieren:

    speyer.de/de/rathaus/medieninf

  14. #Schuldigitalisierung ohne #Cybersecurity: Ende Januar 2025 griff ein Ableger der #Lockbit-#Ransomware den rheinland-pfälzischen IT-Dienstleister Topackt an und verschlüsselte 45 Server. Über zwei Terabyte hochsensibler Schuldaten von mehr als 40 Schulen landeten schließlich im #Darknet.

    Schulen und kommunale Einrichtungen werden von den Bundesländern in Sachen digitaler #Resilienz nach wie vor weitestgehend sich selbst überlassen - sollen aber massiv digitalisieren:

    speyer.de/de/rathaus/medieninf

  15. Thanks to samples provided by @pinkflawd you can now look at the beauty of #Lockbit's obfuscated control-flow via @cfgbot by @tmr232

    RE: https://mastodon.social/@cfgbot/116202847162981925
  16. Thanks to samples provided by @pinkflawd you can now look at the beauty of #Lockbit's obfuscated control-flow via @cfgbot by @tmr232

    RE: https://mastodon.social/@cfgbot/116202847162981925
  17. 🇨🇱 LockBit 5.0 has now published all the information from Clínica Dávila (davila.cl). Remember that this medical institution was attacked by the Devman ransomware back in December last year. It appears that Devman sold a portion of the data to LockBit.

    Now the question that arises: Has Clínica Dávila individually notified each patient about the attack it suffered from Devman back in December last year?

    security-chu.com/2026/03/lockb

    #cybersecurity #ransomware #Chile #databreach #health #healthcare #lockbit #devman #research

  18. 🇨🇱 LockBit 5.0 has now published all the information from Clínica Dávila (davila.cl). Remember that this medical institution was attacked by the Devman ransomware back in December last year. It appears that Devman sold a portion of the data to LockBit.

    Now the question that arises: Has Clínica Dávila individually notified each patient about the attack it suffered from Devman back in December last year?

    security-chu.com/2026/03/lockb

    #cybersecurity #ransomware #Chile #databreach #health #healthcare #lockbit #devman #research

  19. LockBit-Ransomware über Apache-ActiveMQ-Lücke: Angriff in zwei Wellen

    Ein ungepatchter Apache-ActiveMQ-Server wurde zum Einfallstor für einen mehrstufigen Ransomware-Angriff, der sich über knapp 19 Tage erstreckte

    all-about-security.de/lockbit-

    #LockBit #ransomware #apache

  20. Cyberzbóje w święta nie czekają na serniczka. Kolejna polska spółka ofiarą ransomware?

    Zaledwie wczoraj informowaliśmy o potencjalnym kolejnym ataku grupy Safepay, a już dzisiaj trafiła do nas informacja nt. grupy Lockbit 5.0 i prawdopodobnym ataku na polską spółkę – Mosty Katowice Sp. z o.o. Firma to znany lider w branży projektowej i inżynieryjnej w Polsce, działający głównie w budownictwie infrastrukturalnym i usługach...

    #Aktualności #Incydent #Lockbit #Ransomware

    sekurak.pl/cyberzboje-w-swieta

  21. Cyberzbóje w święta nie czekają na serniczka. Kolejna polska spółka ofiarą ransomware?

    Zaledwie wczoraj informowaliśmy o potencjalnym kolejnym ataku grupy Safepay, a już dzisiaj trafiła do nas informacja nt. grupy Lockbit 5.0 i prawdopodobnym ataku na polską spółkę – Mosty Katowice Sp. z o.o. Firma to znany lider w branży projektowej i inżynieryjnej w Polsce, działający głównie w budownictwie infrastrukturalnym i usługach...

    #Aktualności #Incydent #Lockbit #Ransomware

    sekurak.pl/cyberzboje-w-swieta

  22. LockBit 5.0 – nowa infrastruktura, publicznie dostępna lista zhakowanych firm i OPSEC grupy pod znakiem zapytania

    Nie tak dawno na łamach Sekuraka pisaliśmy o sojuszu grup LockBit, DragonForce oraz Qilin i reaktywacji Lockbit 5.0 z zaawansowanym, wieloplatformowym malwarem, wykorzystującym m.in. silne szyfrowanie. Zgodnie z oceną badaczy z Trend Micro, powrót Lockbit stanowi realne zagrożenie oraz może skutkować zwiększoną częstotliwością ataków, o czym mieliśmy okazję się przekonać...

    #Aktualności #Awareness #Lockbit #Opsec #OSINT #Ransomware

    sekurak.pl/lockbit-5-0-nowa-in

  23. LockBit 5.0 – nowa infrastruktura, publicznie dostępna lista zhakowanych firm i OPSEC grupy pod znakiem zapytania

    Nie tak dawno na łamach Sekuraka pisaliśmy o sojuszu grup LockBit, DragonForce oraz Qilin i reaktywacji Lockbit 5.0 z zaawansowanym, wieloplatformowym malwarem, wykorzystującym m.in. silne szyfrowanie. Zgodnie z oceną badaczy z Trend Micro, powrót Lockbit stanowi realne zagrożenie oraz może skutkować zwiększoną częstotliwością ataków, o czym mieliśmy okazję się przekonać...

    #Aktualności #Awareness #Lockbit #Opsec #OSINT #Ransomware

    sekurak.pl/lockbit-5-0-nowa-in

  24. LockBit 5.0: Key IP + Domain Exposed in Rare OPSEC Breakdown
    technadu.com/lockbit-5-0-infra

    Researcher Rakesh Krishnan uncovered and published IP 205.185.116.233 and domain karma0[.]xyz — the backbone of LockBit 5.0’s new leak site. The server runs with open RDP, FTP, HTTP, and other services, exposing glaring vulnerabilities in LockBit’s infrastructure.

    A meaningful win for defenders, enabling immediate blocking and further intelligence gathering.

    #CyberSecurity #ThreatIntel #Ransomware #LockBit #BlueTeam

  25. OFAC + U.K. + Australia sanction Media Land LLC for providing bulletproof hosting to LockBit, BlackSuit, Play, Evil Corp & Black Basta.
    Volosovik (Yalishanda), Zatolokin & Pankova named, along with ML Cloud, MLT & DC Kirishi.

    Full report: technadu.com/russian-hosting-p

    Follow @technadu for continuous threat intel.
    #CybersecurityNews #Ransomware #LockBit #ThreatIntel

  26. OFAC + U.K. + Australia sanction Media Land LLC for providing bulletproof hosting to LockBit, BlackSuit, Play, Evil Corp & Black Basta.
    Volosovik (Yalishanda), Zatolokin & Pankova named, along with ML Cloud, MLT & DC Kirishi.

    Full report: technadu.com/russian-hosting-p

    Follow @technadu for continuous threat intel.
    #CybersecurityNews #Ransomware #LockBit #ThreatIntel

  27. NEW - 🚨 The UK National Crime Agency (#NCA) has exposed and sanctioned Alexander Volosovik, aka “Yalishanda,” for running Russian bulletproof hosting operations linked to LockBit, Evil Corp and BlackBasta ransomware.

    Read: hackread.com/uk-bulletproof-ho

    #CyberSecurity #Ransomware #LockBit #EvilCorp #CyberCrime

  28. "- 85 active ransomware and extortion groups observed in Q3 2025, reflecting the most decentralized ransomware ecosystem to date.

    - 1,590 victims disclosed across 85 leak sites, showing high, sustained activity despite law-enforcement pressure.

    - 14 new ransomware brands launched this quarter, proving how quickly affiliates reconstitute after takedowns.

    - LockBit's reappearance with version 5.0 signals potential re-centralization after months of fragmentation."

    thehackernews.com/2025/11/rans

    #CyberSecurity #Ransomware #Lockbit

  29. Gemäß einer Analyse von Check Point Research weise das dritte Quartal 2025 das bislang dezentralisierteste Ransomware‑Ökosystem auf. Die Untersuchung habe 85 aktive Ransomware‑ und Erpressungsgruppen sowie 1 590 Opfer ergeben, die über 85 Leak‑Seiten publik gemacht worden seien. Und: LockBit mit Version 5.0 ist zurück, woraus ein neuer Trend zur Zentralisierung abgeleitet werden könnte.

    maniabel.work/archiv/232
    #Ransomware #Lockbit #infosec #infosecnews #BeDiS

  30. Защита от шифровальщиков. Как происходят атаки и что делать?

    За последний год даже те, кто не связан с информационной безопасностью или ИТ-администрированием, узнали о хакерских атаках, в ходе которых уничтожаются или шифруются данные. Теоретически, массовая атака программ-вымогателей может временно парализовать важную инфраструктуру: остановить транспорт, лишить магазины, аптеки и АЗС возможности обслуживать клиентов. Хотя такая картина кажется гиперболизированной, она вполне возможна — особенно на фоне недавних событий и произошедших инцидентов. В статье расскажем о масштабах угрозы и о том, как организации могут противостоять атакам программ-вымогателей. На основе реальных расследований поделимся не только техническими деталями, но и практическими рекомендациями, которые помогут снизить риски и вовремя отреагировать на инцидент.

    habr.com/ru/companies/jetinfos

    #кибербезопасность #ransomware #иб #информационная_безопасность #cybersecurity #расследование_инцидентов #soc #phishing #фишинг #lockbit

  31. I like my individualized mail addresses. I just received a phishing mail to update my data with a Swiss payment system (TWINT) - but it was sent to an address I created for a doctor's appointment system (Onedoc).
    The message also contains my postal address from the time I created that account.

    #databreach #switzerland #Onedoc #Lockbit #twint #phishing

  32. Kolejny sojusz przestępczy. Grupy LockBit, DragonForce i Qilin łączą siły

    Nie tak dawno pisaliśmy o sojuszu trzech grup cyberprzestępczych, działających pod nazwą Scattered Lapsus$ Hunters, a już na horyzoncie pojawia się kolejne zagrożenie – powrót grupy LockBIt, tym razem we współpracy z DragonForce oraz Qilin. O LockBicie było głośno w 2024 r., kiedy to w ramach międzynarodowej operacji Cronos, udało...

    #WBiegu #Awareness #Dragonforce #Lockbit #Qilin #Ransomware #Sojusz

    sekurak.pl/kolejny-sojusz-prze