LockBit ransomware hunts Windows domains and subverts Microsoft Defender

Surface Laptop 4 Amd 2021 HeroSource: Daniel Rubino / Windows Central

Cyberthreats such as ransomware grow more devilish by the day. Case in point: LockBit 2.0, a specific breed of ransomware-as-a-service that’s escalated the stakes associated with suffering a ransomware attack.

As reported by BleepingComputer, LockBit’s been around for a while. As far back as 2019, it was stirring up trouble, offering 70-80% revenue shares to affiliates who used the service-based ransomware while breaching networks and encrypting devices, with the actual developers reaping whatever remained from the software’s haul.

LockBit’s evolved since those days, keeping up with the latest tech and trends. Now, the world is faced with LockBit 2.0, which can not only encrypt networks via group policy updates but can hijack connected printers to print a non-stop stream of ransom notes (a ransomware feature seemingly designed to get victims’ attention).

VPN Deals: Lifetime license for $16, monthly plans at $1 & more

While the printer spam is self-explanatory, here’s a more detailed breakdown of that network encryption item. When bad guys take the reins of a domain controller, LockBit 2.0 then distributes itself to domains. It will create new group policies that cut off Microsoft Defender and its defense mechanisms and create policies that launch the ransomware.

“This is the first ransomware operation to automate this process, and it allows a threat actor to disable Microsoft Defender and execute the ransomware on the entire network with a single command,” ethical hacker Vitali Kremez told BleepingComputer.

In short: LockBit 2.0 is no joke, much like other recent security-related concerns to crop up in the Windows-verse, such as how researchers have exposed a TPM-related chink in the armor of corporate Windows laptops (which may or may not present issues for Windows 11).

Leave a Reply

Your email address will not be published. Required fields are marked *