LockFile — Ransomware Profile

LockFile is a ransomware family that Symantec documented in August 2021 after first observing it on the network of a U.S. financial organization on 20 July 2021, describing it at the time as what appeared to be a new family being used against victims worldwide. Its operators appear to have chained the ProxyShell flaws in on-premises Microsoft Exchange for initial access with an exploit for CVE-2021-36942, the PetitPotam NTLM relay bug, to take over the Windows domain controller before pushing the payload out across the network. Sophos found that the encryptor scrambles every other 16 bytes of a file rather than the whole thing — a technique its researchers called intermittent encryption and had not seen before — which leaves an encrypted document statistically close enough to the original to slip past some ransomware protection products. The ransom note closely resembled LockBit 2.0's, while the contact address sat on the domain contipauper.com, read by Sophos as a dig at the rival Conti operation. Symantec placed the victims in manufacturing, financial services, engineering, legal, business services and travel and tourism; Secureworks CTU subsequently assessed that BRONZE STARLIGHT was likely behind the LockFile activity, one of five short-lived ransomware brands that each hit a handful of victims over a brief window before shutting down apparently for good.

IntelFusions coverage (4)

Vendor research

Read the full analysis on IntelFusions