The leak of the builder for the latest encryptor of the LockBit ransomware gang made the headlines, it seems that the person who published it is a disgruntled developer.
The latest version of the encryptor, version 3.0, was released by the gang in June. According to the gang, LockBit 3.0 has important novelties such as a bug bounty program, Zcash payment, and new extortion tactics. The gang has been active since at least 2019 and today it is one of the most active ransomware gangs.
The code of the encryptor was leaked on Twitter by at least a couple of accounts, @ali_qushji and @protonleaks1.
The builder is contained in a password-protected 7z archive, “LockBit3Builder.7z,” containing:
Ali Qushji claims to have hacked the servers of the ransomware gang and stolen the ransomware encryptor.
Is the hack real?
BleepingComputer reported that the research team VX-Underground was informed by a representative of the LockBit operation that their infrastructure was not hacked. The representative added that the leak is the work of a disgruntled developer.
“We reached out to Lockbit ransomware group regarding this and discovered this leaker was a programmer employed by Lockbit ransomware group,” reads a now deleted tweet published by VX-Underground. “They were upset with Lockbit leadership and leaked the builder.”
The availability of the builder could allow any malicious actor to create its own version of the ransomware customizing it by modifying the configuration file.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, data leak)
[adrotate banner=”5″]
[adrotate banner=”13″]
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…
This website uses cookies.