• About
  • Privacy Policy
Open Security Labs
No Result
View All Result
No Result
View All Result
Open Security Labs
No Result
View All Result
Home Uncategorized

Kulicke & Soffa Targeted by LockBit Ransomware: What You Need to Know? (May 24, 2024)

Hriday Nakka by Hriday Nakka
27th May 2024
in Uncategorized
0
Kulicke & Soffa Targeted by LockBit Ransomware: What You Need to Know? (May 24, 2024)
483
SHARES
1.6k
VIEWS
Share on FacebookShare on Twitter
  1. Company Overview:
  2. Understanding the Ransomware
    1. Definition:
    2. History and Evolution:
    3. Ransomware-as-a-Service (RaaS):
  3. How the Ransomware Works
  4. Stages of LockBit Attacks:
  5. Protecting Against LockBit Ransomware

On May 24, 2024, the LockBit ransomware group declared they had infiltrated the Singaporean manufacturing company Kulicke & Soffa (KNS.com), listing it as a victim on their dark web leak site. They set a ransom deadline of June 7, 2024, at 14:06:03 UTC.

Company Overview:

  • Name: Kulicke & Soffa
  • Website: kns.com
  • Founded: 1951
  • Headquarters: Singapore
  • Industry: Semiconductor and Electronics Manufacturing
  • Ticker: NASDAQ: KLIC

LockBit claims to have infiltrated KNS.com’s network over several months, gathering over 20 terabytes of sensitive data, equivalent to over 12 million files from more than 2,000 devices. This data includes:

  • Source codes from Git, SVN, and Nexus repositories
  • Jira, Bamboo, and Confluence data
  • Information related to lasers, microscopes, lithography, analyzers, and 2D/3D files
  • Mail backups, databases, archives, documents, user shares, personal files, and chats
  • Files related to clients and partners, including the partnership with i3 and critical products like Liteq 500
  • Financial and accounting records

They assert that they have accessed everything, including internal and customer correspondence, from servers and devices linked to the engineers, R&D, and production departments across multiple countries, including the US, Netherlands, Germany, Switzerland, Singapore, China, India, Israel, Malaysia, the Philippines, and others.

Understanding the Ransomware

Definition:

LockBit ransomware is malicious software that blocks user access to computer systems in exchange for a ransom payment. It automatically targets valuable systems, spreads the infection, and encrypts all accessible computer systems on a network. LockBit is used for highly targeted attacks against enterprises and organizations, posing threats such as operational disruption, financial extortion, and data theft.

History and Evolution:

LockBit, formerly known as “ABCD” ransomware, has evolved into a significant threat since its inception in September 2019. Initially dubbed the “.abcd virus” due to the file extension used when encrypting files, LockBit targets enterprises and government organizations rather than individuals. Notable past targets include organizations in the US, China, India, Indonesia, Ukraine, and various European countries.

Ransomware-as-a-Service (RaaS):

LockBit operates under a RaaS model, where affiliates can rent the ransomware for custom attacks. Ransom payments are shared between the LockBit developers and the attacking affiliates, with affiliates receiving up to 75% of the ransom.

How the Ransomware Works

LockBit is considered part of the “LockerGoga & MegaCortex” malware family, sharing behaviors with these established forms of targeted ransomware. LockBit is known for its self-propagating ability, meaning it spreads automatically within an organization without manual intervention. After manually infecting a single host, the ransomware can find and infect other accessible hosts using a script.

The ransomware uses tools commonly found on Windows systems, making it difficult for endpoint security systems to detect malicious activity. It disguises the executable encrypting file as a .PNG image file format, further deceiving system defenses.

Stages of LockBit Attacks:

  1. Exploit
  2. Infiltrate
  3. Deploy

Protecting Against LockBit Ransomware

To protect against ransomware attacks like LockBit, organizations should implement robust cybersecurity measures:

  1. Strong Passwords:
    • Use secure passwords with character variations and self-created rules to craft passphrases.
  2. Multi-Factor Authentication (MFA):
    • Add layers atop initial password-based logins, including biometrics or physical USB key authenticators.
  3. Reassess User Account Permissions:
    • Limit permissions to reduce potential threats, focusing on endpoint users and IT accounts with admin-level permissions.
  4. Clean Outdated User Accounts:
    • Remove old accounts to eliminate potential weak points.
  5. Ensure Security Procedures:
    • Regularly review system configurations and standard operation procedures to stay current against new cyber threats.
  6. System-Wide Backups:
    • Maintain offline backups and clean local machine images. Regularly create backups to keep up-to-date with important changes.
  7. Comprehensive Cybersecurity Solutions:
    • Implement enterprise cybersecurity protection software to detect and prevent malware infections across the organization.

For more information on protecting your business, consider exploring Kaspersky Security Solutions for Enterprises, which offer real-time protection against threats like LockBit ransomware.

By staying vigilant and implementing these protective measures, organizations can bolster their defenses against ransomware attacks and mitigate potential damage.

Lockbit

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Email a link to a friend (Opens in new window) Email

Related


Discover more from Open Security Labs

Subscribe to get the latest posts sent to your email.

Previous Post

The Rise and Fall of Rabbit R1: Why Was There So Much Hype Around the $200 Orange Device?

Next Post

Security Flaw in Check Point VPNs Risks Corporate Networks (0)

Related Posts

CyberStalking
Uncategorized

The Dark Reality of Cyberstalking: How to Stay Safe on Social Media (0penBuckets)

29th December 2024
Volkswagen
Uncategorized

Massive Data Exposure from Volkswagen Electric Cars Highlights Cloud Security Risks (0penBuckets)

29th December 2024
amazon
Uncategorized

Dangerous Android Malware Found on Amazon Appstore – Steals Your Data in Disguise! (0penBuckets)

21st December 2024
Live Sports
Uncategorized

Massive Live Sports Piracy Ring Shut Down – Over 821 Million Visits Annually!”

21st December 2024
BellaCPP
Uncategorized

BellaCPP: The C++ Malware That’s Redefining Cyber Threats (0penBuckets)

21st December 2024
Docker
Uncategorized

Mastering Docker Security: Essential Tips for Unbreakable Containers (0penBuckets)

21st December 2024
Next Post
VPN

Security Flaw in Check Point VPNs Risks Corporate Networks (0)

Leave a ReplyCancel reply

  • About
  • Privacy Policy

© 2024 OpenSecurityLabs.com

No Result
View All Result
  • About
  • Privacy Policy

© 2024 OpenSecurityLabs.com

Discover more from Open Security Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Open Security Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading

Loading Comments...