LockBit 3.0
Defensive profile aggregated solely from the catalogued evidence. Associations reflect the sources and are not independent EudorIA attribution.
- Evidence status
- observed
- First observation
- Not available
- Last observation
- 21/11/2023
- Correlated signals
- 2
What the sources describe
Cybersecurity Advisory #StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability Release Date November 21, 2023 Alert Code AA23-325A Related topics: Cyber Threats and Response , Multifactor Authentication , Cybersecurity Best Practices SUMMARY Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Multi-State Information Sharing & Analysis Center (MS-ISAC), and Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) are releasing this joint Cybersecurity Advisory (CSA) to disseminate IOCs, TTPs, and detection methods associated with LockBit 3.0 ransomware exploiting CVE-2023-4966, labeled Citrix Bleed, affecting Citrix NetScaler web application delivery control (ADC) and NetScaler Gateway appliances. This CSA provides TTPs and IOCs obtained from FBI, ACSC, and voluntarily shared by Boeing. Boeing observed LockBit 3.0 affiliates exploiting CVE-2023-4966, to obtain initial access to Boeing Distribution Inc., its parts and distribution business that maintains a separate environment. Other trusted third parties have observed similar activity impacting their organization. Historically, LockBit 3.0 affiliates have conducted attacks a
Cybersecurity Advisory #StopRansomware: LockBit 3.0 Release Date March 16, 2023 Alert Code AA23-075A Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response Actions to take today to mitigate cyber threats from ransomware: Prioritize remediating known exploited vulnerabilities. Train users to recognize and report phishing attempts. Enable and enforce phishing-resistant multifactor authentication. SUMMARY Note: this joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing & Analysis Center (MS-ISAC) are releasing this joint CSA to disseminate known LockBit 3.0 ransomware IOCs and TTPs identified through FBI investigations as recently as March 2023. The LockBit 3.0 ransomware operations function as a Ransomware-as-a-Service (RaaS) model and is a continuation of previous versions of the ransomware, LockBit 2.0, and LockBit. Since January 2020, LockBit has functioned as an affiliate-based ransomware variant; affiliates deploying the LockBit RaaS use many varying TTPs and attack a wide range of businesses and critical infrastructure organizations, which can make effective computer network defense and mitigation challenging. The FBI, CISA, and the MS-IS
Observed methods and techniques
T1082T1539T1556.006T1563T1003.001T1021.001T1027T1046T1048T1070.004T1071.002T1072T1078T1133T1189T1190T1480.001T1485T1486T1489T1490T1491.001T1547T1566T1567T1567.002T1572T1614.001How to prepare the defence
The sources contain no explicit defensive guidance. The services below are deterministically correlated to the catalogued TTPs, not generated as claims about the actor.
Security Assessment
Verifica esposizione, configurazioni e priorita di remediation prima che una tecnica osservata diventi un incidente.
Approfondisci il servizio →Managed WAF
Protegge applicazioni e API esposte con regole gestite, virtual patching e analisi degli eventi applicativi.
Approfondisci il servizio →Identity Security Managed
Riduce abuso di credenziali e accessi anomali con MFA, controllo delle identita e verifica continua.
Approfondisci il servizio →Backup e continuita operativa
Prepara copie isolate, prove di ripristino e procedure operative per limitare l'impatto di cifratura o distruzione.
Approfondisci il servizio →The measures listed reduce likelihood and impact but do not guarantee the absolute prevention of an attack.
Public sources
Catalogued onion sources
No onion source associated with this group.
Linked observations
| Date | Signal | Type | Confidence |
|---|---|---|---|
| 21/11/2023 | #StopRansomware: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability | ransomware | official |
| 16/03/2023 | #StopRansomware: LockBit 3.0 | ransomware | official |