Thanks to samples provided by @pinkflawd you can now look at the beauty of #Lockbit's obfuscated control-flow via @cfgbot by @tmr232

RE: https://mastodon.social/@cfgbot/116202847162981925

🇨🇱 LockBit 5.0 has now published all the information from Clínica Dávila (http://davila.cl). Remember that this medical institution was attacked by the Devman ransomware back in December last year. It appears that Devman sold a portion of the data to LockBit.

Now the question that arises: Has Clínica Dávila individually notified each patient about the attack it suffered from Devman back in December last year?

https://www.security-chu.com/2026/03/lockbit-filtra-los-datos-de-la-clinica-davila.html

#cybersecurity #ransomware #Chile #databreach #health #healthcare #lockbit #devman #research

@cwebber personally I consider using #OpenClaw an act of criminal sabotage not dissimilar of #AffiliateMalware like #LockBit and installing #Shitciin - #Mining #malware

Threat Actors Exploit Apache ActiveMQ Server Vulnerability to Gain RDP Access and Deploy LockBit Ransomware

Pulse ID: 69a19efa5a3cb45c05190273
Pulse Link: https://otx.alienvault.com/pulse/69a19efa5a3cb45c05190273
Pulse Author: CyberHunter_NL
Created: 2026-02-27 13:41:13

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#APAC #ActiveMQ #Apache #CyberSecurity #InfoSec #LockBit #OTX #OpenThreatExchange #RDP #RansomWare #Vulnerability #bot #CyberHunter_NL

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Apache ActiveMQ Exploit Leads to LockBit Ransomware - The DFIR Report

Pulse ID: 69a19f09b3ea1e782cb3e96f
Pulse Link: https://otx.alienvault.com/pulse/69a19f09b3ea1e782cb3e96f
Pulse Author: CyberHunter_NL
Created: 2026-02-27 13:41:29

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#APAC #ActiveMQ #Apache #CyberSecurity #InfoSec #LockBit #OTX #OpenThreatExchange #RansomWare #bot #CyberHunter_NL

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Apache ActiveMQ Exploit Leads to LockBit Ransomware

Pulse ID: 699d3e6224da5f2edf580175
Pulse Link: https://otx.alienvault.com/pulse/699d3e6224da5f2edf580175
Pulse Author: Tr1sa111
Created: 2026-02-24 06:00:02

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#APAC #ActiveMQ #Apache #CyberSecurity #InfoSec #LockBit #OTX #OpenThreatExchange #RansomWare #bot #Tr1sa111

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Apache ActiveMQ Exploit Leads to LockBit Ransomware

A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server, gaining initial access and later returning after being evicted. The attacker used Metasploit for post-exploitation activities, including privilege escalation, credential access, and lateral movement. Upon regaining access, they swiftly deployed LockBit ransomware via RDP using previously extracted credentials. The ransomware binary matched LockBit signatures but was likely crafted using the leaked LockBit builder, as evidenced by modified ransom notes and communication methods. The intrusion spanned 19 days from initial access to ransomware deployment, with less than 90 minutes between re-engagement and encryption during the second phase.

Pulse ID: 699cd6eed9db04bd8dc60dc9
Pulse Link: https://otx.alienvault.com/pulse/699cd6eed9db04bd8dc60dc9
Pulse Author: AlienVault
Created: 2026-02-23 22:38:38

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#APAC #ActiveMQ #Apache #CyberSecurity #Encryption #InfoSec #LockBit #OTX #OpenThreatExchange #RDP #RansomWare #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

LockBit-Ransomware über Apache-ActiveMQ-Lücke: Angriff in zwei Wellen

Ein ungepatchter Apache-ActiveMQ-Server wurde zum Einfallstor für einen mehrstufigen Ransomware-Angriff, der sich über knapp 19 Tage erstreckte

https://www.all-about-security.de/lockbit-ransomware-ueber-apache-activemq-luecke-angriff-in-zwei-wellen/

#LockBit #ransomware #apache

LockBit-Ransomware über Apache-ActiveMQ-Lücke: Angriff in zwei Wellen

CVE-2023-46604 ermöglichte Angreifern zweimaligen Zugriff auf einen ActiveMQ-Server – am Ende stand der Einsatz von LockBit-Ransomware.

All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing, IT-Sicherheit, Netzwerksicherheit, KI, Threats, DDoS, Identity & Access, Plattformsicherheit

LockBit strikes with new 5.0 version, targeting Windows, Linux and ESXI systems

Pulse ID: 6992a5f5ad58f2ee182e3ed1
Pulse Link: https://otx.alienvault.com/pulse/6992a5f5ad58f2ee182e3ed1
Pulse Author: Tr1sa111
Created: 2026-02-16 05:07:01

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #Linux #LockBit #OTX #OpenThreatExchange #Windows #bot #Tr1sa111

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange