On May 24, 2024, the LockBit ransomware group declared they had infiltrated the Singaporean manufacturing company Kulicke & Soffa (KNS.com), listing it as a victim on their dark web leak site. They set a ransom deadline of June 7, 2024, at 14:06:03 UTC.
Company Overview:
- Name: Kulicke & Soffa
- Website: kns.com
- Founded: 1951
- Headquarters: Singapore
- Industry: Semiconductor and Electronics Manufacturing
- Ticker: NASDAQ: KLIC
LockBit claims to have infiltrated KNS.com’s network over several months, gathering over 20 terabytes of sensitive data, equivalent to over 12 million files from more than 2,000 devices. This data includes:
- Source codes from Git, SVN, and Nexus repositories
- Jira, Bamboo, and Confluence data
- Information related to lasers, microscopes, lithography, analyzers, and 2D/3D files
- Mail backups, databases, archives, documents, user shares, personal files, and chats
- Files related to clients and partners, including the partnership with i3 and critical products like Liteq 500
- Financial and accounting records
They assert that they have accessed everything, including internal and customer correspondence, from servers and devices linked to the engineers, R&D, and production departments across multiple countries, including the US, Netherlands, Germany, Switzerland, Singapore, China, India, Israel, Malaysia, the Philippines, and others.
Understanding the Ransomware
Definition:
LockBit ransomware is malicious software that blocks user access to computer systems in exchange for a ransom payment. It automatically targets valuable systems, spreads the infection, and encrypts all accessible computer systems on a network. LockBit is used for highly targeted attacks against enterprises and organizations, posing threats such as operational disruption, financial extortion, and data theft.
History and Evolution:
LockBit, formerly known as “ABCD” ransomware, has evolved into a significant threat since its inception in September 2019. Initially dubbed the “.abcd virus” due to the file extension used when encrypting files, LockBit targets enterprises and government organizations rather than individuals. Notable past targets include organizations in the US, China, India, Indonesia, Ukraine, and various European countries.
Ransomware-as-a-Service (RaaS):
LockBit operates under a RaaS model, where affiliates can rent the ransomware for custom attacks. Ransom payments are shared between the LockBit developers and the attacking affiliates, with affiliates receiving up to 75% of the ransom.
How the Ransomware Works
LockBit is considered part of the “LockerGoga & MegaCortex” malware family, sharing behaviors with these established forms of targeted ransomware. LockBit is known for its self-propagating ability, meaning it spreads automatically within an organization without manual intervention. After manually infecting a single host, the ransomware can find and infect other accessible hosts using a script.
The ransomware uses tools commonly found on Windows systems, making it difficult for endpoint security systems to detect malicious activity. It disguises the executable encrypting file as a .PNG image file format, further deceiving system defenses.
Stages of LockBit Attacks:
- Exploit
- Infiltrate
- Deploy
Protecting Against LockBit Ransomware
To protect against ransomware attacks like LockBit, organizations should implement robust cybersecurity measures:
- Strong Passwords:
- Use secure passwords with character variations and self-created rules to craft passphrases.
- Multi-Factor Authentication (MFA):
- Add layers atop initial password-based logins, including biometrics or physical USB key authenticators.
- Reassess User Account Permissions:
- Limit permissions to reduce potential threats, focusing on endpoint users and IT accounts with admin-level permissions.
- Clean Outdated User Accounts:
- Remove old accounts to eliminate potential weak points.
- Ensure Security Procedures:
- Regularly review system configurations and standard operation procedures to stay current against new cyber threats.
- System-Wide Backups:
- Maintain offline backups and clean local machine images. Regularly create backups to keep up-to-date with important changes.
- Comprehensive Cybersecurity Solutions:
- Implement enterprise cybersecurity protection software to detect and prevent malware infections across the organization.
For more information on protecting your business, consider exploring Kaspersky Security Solutions for Enterprises, which offer real-time protection against threats like LockBit ransomware.
By staying vigilant and implementing these protective measures, organizations can bolster their defenses against ransomware attacks and mitigate potential damage.

Discover more from Open Security Labs
Subscribe to get the latest posts sent to your email.







