LockFile Ransomware
Summary
The final payload delivered to the compromised systems is a new strain of ransomware named LockFile. Earlier LockFile infections delivered a non-branded ransom note with typical demands of payment using the Bitcoin cryptocurrency. As communication channels, the LockFile gang leaves a TOX account ID and the contact@contipauper.com email address. To establish an initial foothold on the targeted computers, the LockFile threat actor leverages the ProxyShell vulnerabilities, CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207. However, recently unveiled technical details have made it possible for threat actors to replicate the exploit.
Classifications
industries
Entertainment
applications
Customer Service & Support
AskAI Classifications
Labels
Cybersecurity Software
Anti-Malware Software
SaaS Security
Linked Companies
EnigmaSoft
$1M to $5M