PULSE NAME
Lockbit Ransomware, Why You No Spread?
WHITE AmiraMohammad 2020-06-30 Modified: 2020-07-30
0
IOCs
LOW VOLUME
RDP brute forcing continues to be a favorite entry point for ransomware actors. In this past month we saw activity from the Lockbit ransomware family. RDP login from 165.231.142.36. Threat actor logged in, then switched accounts to a DA 15 minutes later. Unlike other actors we’ve seen in the lab or in other reports take meticulous inventory and thoroughly enumerate a victim environment this actor moved straight into final phase activity.
Indicators of Compromise (0)
All
No indicators.