LockBit

Summary
Ransomware from the LockBit ransomware group
Class
Ransomware
Class Summary
Ransomware is a form of malicious software that encrypts files on your device, making them inaccessible. The attacker then demands a ransom to decrypt the files. If ransomware is detected, make note that there is no guarantee the attacker will provide the decryption key upon paying the ransom. Disconnect the affected system from your network to prevent the spread of the ransomware, and consult with a security specialist. Regular backups are key in recovering from ransomware attacks.
Description

Described by VXUnderground as a milestone—the first instance of a major ransomware group targeting Apple products—LockBit appears to be an Apple port of its Linux counterpart, first surfacing in early 2022. Initial samples displayed ad hoc signing, triggering an invalid signature pop-up upon execution. As of the latest information, LockBit does not yet exfiltrate data and is believed to be under active development, suggesting additional functionalities could be forthcoming. When successfully executed, the ransomware encrypts files using open-source TLS libraries and leaves a ransom note in a file labeled "!!!-Restore-My-Files-!!!".

Example Hashes
  • 2d15286d25f0e0938823dcd742bc928e78199b3d
  • 864f56b25a34e9532a1175d469715d2f61c56f7f