Security News > 2022 > April > Attackers unleash LockBit ransomware on US government computers
Attackers unleash LockBit ransomware on US government computers.
One attack highlighted in the report found that ransomware groups spend at least five months combing through a regional U.S. government agency's files and system before deploying a LockBit attack onto the affected computer.
"Working together with the target, Sophos researchers were able to build a picture that started with what appears to be novice attackers breaking into the server, poking around the network and using the compromised server to Google a combination of pirated and free versions of hacker and legitimate admin tools to use in their attack."
The one silver lining in this situation was that the attackers seemed inexperienced and not sure what to do after gaining access to the government network.
"The most important first step is to try to prevent attackers from gaining access to a network in the first place, for example by implementing multi-factor authentication and setting firewall rules to block remote access to RDP ports in the absence of a VPN connection. If a member of the IT team hasn't downloaded them for a specific purpose, the presence of tools on machines on your network is a red flag for an ongoing or imminent attack."
Also See Share: Attackers unleash LockBit ransomware on US government computers.
News URL
Related news
- US charges Russian-Israeli as suspected LockBit ransomware coder (source)
- US charges suspected LockBit ransomware developer (source)
- US charges Phobos ransomware admin after South Korea extradition (source)
- Phobos ransomware administrator faces US cybercrime charges (source)
- Russian suspected Phobos ransomware admin extradited to US over $16M extortion (source)
- Mega US healthcare payments network restores system 9 months after ransomware attack (source)
- Wanted Russian Hacker Linked to Hive and LockBit Ransomware Arrested (source)
- US government, energy sector contractor hit by ransomware (source)
- Vodka maker Stoli files for bankruptcy in US after ransomware attack (source)
- US sanctions Chinese firm for hacking firewalls in ransomware attacks (source)