← Threat Actors & APT Groups

LockBit

Every article that identifies LockBit as responsible for or connected to reported activity.

RansomwareThe DFIR Report·6 months ago

Apache ActiveMQ Exploit Leads to LockBit Ransomware

A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, ultimately leading to LockBit ransomware deployment. The DFIR Report provides a detailed analysis of this intrusion chain, including insights into the attacker's techniques and methodology.