Unfiltered look into LockBit’s operations
Essential information
- Published
- 15/05/2025 22:59
- Modified
- 21/05/2025 20:42
- Tags
- 2025-05-15 affiliate panels dark web data breach initial access brokers lockbit negotiation tactics ransomware
- Related entities
- 3 observables, 1 intrusion sets (apt), 14 techniques (mitre), 1 malware
Description
A breach of LockBit's dark web affiliate panels exposed a rare glimpse into their operations. The leaked data included Bitcoin addresses, admin credentials, and a chat log revealing negotiation tactics and ransom demands. Ransom amounts varied widely, with some victims confused about the demands. The breach exposed LockBit's research into victims' finances and their willingness to provide additional services for a fee. The incident highlights the complexities of cybercrime negotiations and the human stories behind the headlines. Additionally, Cisco Talos observed a trend of attack kill chains being split into two stages, executed by separate threat actors, leading to refined definitions of initial access brokers.