Security News > 2021 > November > Lockean multi-ransomware affiliates linked to attacks on French orgs

Lockean multi-ransomware affiliates linked to attacks on French orgs
2021-11-04 11:22

Details about the tools and tactics used by a ransomware affiliate group, now tracked as Lockean, have emerged today in a report from France's Computer Emergency Response Team.

Lockean activity was first noticed in 2020 when the actor hit a French company in the manufacturing sector and deployed DoppelPaymer ransomware on the network.

Between June 2020 and March 2021, Lockean attacked at least seven more companies with various ransomware families: Maze, Egregor, ProLock, REvil.

Four additional companies, unnamed by CERT-FR, were identified as victims of Lockean from reports to ANSSI, France's national cybersecurity agency, and two incidents described by private organizations Intrinsec and The DFIR Report.

In most of the attacks described in the report, the threat actor gained initial access to the victim network through Qbot/QakBot, a banking trojan that changed its role to distribute other malware, including ransomware strains ProLock, Egregor, and DoppelPaymer.

Lockean is the second ransomware affiliate identified this year.


News URL

https://www.bleepingcomputer.com/news/security/lockean-multi-ransomware-affiliates-linked-to-attacks-on-french-orgs/