Skip to main content
Lockbit

Lockbit

Search complete. 20 mentions across 9 episodes found for "Lockbit".

Sep 15, 2026

David MorrowHOST
36:28
how they have basically built an internal search so that people can find and slice their data for all of the victim data, right? That's something very unique.
David MorrowHOST
36:37
And then you've got LockBit 3.0. Another researcher was talking to us about LockBit, LockBit 3.0, and how they've developed this LockBit Black, which really
Christian RodriguezGUEST
36:46
eliminates the need for IABs.
David MorrowHOST
36:49
They won't even need initial access brokers.
David BombalHOST
0:21
What's your advice to someone who's interested in becoming you?
Jon DiMaggioGUEST
0:24
Well, the first piece of advice I wanna give, LockBit took down a children's, uh, cancer hospital.
Jon DiMaggioGUEST
0:30
A- and that, y- those feelings, the ...
Jon DiMaggioGUEST
0:33
I wrote, "I am hate, I am rage, I am vengeance."
David BombalHOST
1:45
Yep.
Jon DiMaggioGUEST
1:45
Uh, went out, went out to the dark web, started looking at bad guys and profiling 'em, and I realized a lot of these guys were, were accessible and would talk.
Jon DiMaggioGUEST
1:53
So I started creating s- fake personas, uh, spending time with them, trying to join ransomware gangs, uh, and I got in with a group called LockBit.
Jon DiMaggioGUEST
2:01
Now, after about six months, I published a report, foolishly put my name on it [laughs] and, uh, the next day they had a new avatar, uh, on their account on the dark web with my face on it.
John DiMaggioGUEST
29:27
And then, you know, I guess the second point, you know, that the indicted affiliate, Bastard Lord.
John DiMaggioGUEST
29:33
He died last year, big time affiliate for LockBit.
John DiMaggioGUEST
29:36
He had worked for the Revo ransomware game previously and others.
John DiMaggioGUEST
29:39
With him, he was like, you know, the first payment, big payment I got was 150,000 cryptocurrency.
John DiMaggioGUEST
31:48
They go after those hospitals.
John DiMaggioGUEST
31:50
And, you know, when I was at DEFCON, I talked about this extensively.
John DiMaggioGUEST
31:53
But the biggest sort of the end of my fallout with LockBit was, you know, when they had attacked St. Anthony's Hospital in Chicago.
John DiMaggioGUEST
32:03
And it has a children's cancer ward.
Tyler MoffittHOST
10:35
They're going for data exfiltration, uh, because the target in which they have been assigned has a purpose and value in the data they're going after.
Tyler MoffittHOST
10:42
However, then there's sort of the maybe kind of complicate, obfuscate where we've seen, like LockBit, for example, Ransomhub, I think even Sodinokibi.
Tyler MoffittHOST
10:55
This is a while back.
Tyler MoffittHOST
10:57
There are threat actor groups out there whose ransomware as a service ecosystem has f- got their affiliates and will, for the most part, target people for money, return on investment, ROI.
Marc Jason GrensGUEST
8:45
Where we're seeing a risk of either re-extortion or threat actors not being good in their promise are those that are in the unknown game.
Marc Jason GrensGUEST
8:53
So after Black Hat went offline and LockBit, got sanctioned and they shut down, you saw a lot of affiliates say, I'm not going to hook up with another affiliate.
Marc Jason GrensGUEST
9:05
I'm going to go and try it on my own.
Marc Jason GrensGUEST
9:07
As you know, there's so much leaked code and malware out there.
Marc Jason GrensGUEST
9:10
LockBit's got multiple versions out there, as well as Black Hat and other variants toolkits that are leaked, are using to say, I'm just going to go and attack myself.
Marc Jason GrensGUEST
9:19
They're not part of a playbook.
Marc Jason GrensGUEST
9:20
So typically when we see that, we usually throw flags on that to state that there's a much higher risk because this is not a well known affiliate.
David ShipleyHOST
3:40
PaperCut has been here before.
David ShipleyHOST
3:42
Its servers were hammered in twenty twenty-three through an authentication bypass flaw, attacks eventually linked to Clop, LockBit, Iranian state backed groups, and the bloody ransomware gang.
David ShipleyHOST
3:55
PaperCut has now put CVE numbers and technical details on the table.
David ShipleyHOST
4:00
CVE-2026-81578 is a high severity authentication bypass in the web management interface, rated eight point eight out of ten.
David HollingworthHOST
17:37
Yeah,
Daniel CroftHOST
17:37
LockBit could never.
Daniel CroftHOST
17:38
LockBit could not stand to the numbers that these guys are achieving.
David HollingworthHOST
17:42
comes close because the way they do mass compromise.
David HollingworthHOST
17:45
Yeah, they do, yeah.
Cyber CowboyHOST
13:42
DFIR, if you don't know, is their digital forensics and incident response team, just in case some of our listeners weren't tracking that acronym.
Cyber CowboyHOST
13:52
And CLOP and LockBit, for those that don't know, are some of the top ransomware as a service actors.
Cyber CowboyHOST
13:59
They don't just do ransomware, but data theft, right? Take it and then hold it hostage until they pay.
Cyber CowboyHOST
14:05
And they attack global organizations.
David HollingworthHOST
19:16
Yeah,
Daniel CroftHOST
19:17
LockBit could never.
Daniel CroftHOST
19:18
LockBit could not stand to the numbers that these guys are achieving.
David HollingworthHOST
19:22
comes close because the way they do there, they do mass compromise.
David HollingworthHOST
19:25
Yeah, they do, yeah.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.