Infosec in brief The infamous LockBit ransomware gang has been busy in the ten days since an international law enforcement operation took down many of its systems. But despite its posturing, the gang might have suffered more than it's letting on. While there have been plenty of revelations – and disappointments – since law enforcement seized LockBit's website and disrupted its operations on February 20, the gang has done anything but vanish. LockBit quickly set up a new website and updated it with a list of forthcoming victim ransom deadlines – one of which included data allegedly stolen from Fulton County, Georgia. Among that data, LockBit claimed, was information about former president Donald Trump's ongoing court cases in the county, which LockBit claimed could have affected the 2024 presidential election. But the February 29 deadline for Fulton County to pay the ransom came and went without any data being published. LockBit claimed Fulton County paid the ransom to prevent data being exposed, but Fulton County officials protested they did no such thing – nor did they use an intermediary to pay the group. Brett Callow, threat analyst with Emsisoft, suggested that rather than the ransom getting paid, it's more likely whatever data LockBit may have had on Fulton County or Donald Trump was seized by law enforcement earlier this month. "I think it was a case of them trying to convince their affiliates that they were still in good shape," Callow told Krebs on Security. Whether L...
LockBit's contested claim of fresh ransom payment suggests it's been well hobbled
The Register
·Brandon Vigliarolo
·Published Mar 4, 2024
·Updated
Affected Software
4 affected components
Cisco NX-OS datacenter operating system
Ivanti Integrity Checker Tool
SolarWinds software
Microsoft Entra ID