LockFile Ransomware

General News

Summary

The final payload delivered to the compromised systems is a new strain of ransomware named LockFile. Earlier LockFile infections delivered a non-branded ransom note with typical demands of payment using the Bitcoin cryptocurrency. As communication channels, the LockFile gang leaves a TOX account ID and the contact@contipauper.com email address. To establish an initial foothold on the targeted computers, the LockFile threat actor leverages the ProxyShell vulnerabilities, CVE-2021-34473, CVE-2021-34523 and CVE-2021-31207. However, recently unveiled technical details have made it possible for threat actors to replicate the exploit.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M