LockData is a financially motivated ransomware group identified by its consistent use of double extortion tactics. The group emerged with documented activity in late 2021, distinguishing itself by systematically exfiltrating sensitive data from victim networks before initiating encryption. This strategy allows them to demand ransom for both data decryption and a guarantee against public disclosure. LockData has increasingly utilized supply chain attacks as a primary method for initial access and broader network propagation.
Tecnicas MITRE
T1486, T1040, T1071.001, T1027
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationSoftware PublishersManufacturingPublic AdministrationEducational ServicesWholesale TradeData Processing Services