Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Botnet Delivers LockBit Black Ransomware

May 10, 2024
Reading Time: 3 mins read
in Alerts
Botnet Delivers LockBit Black Ransomware

Since April, millions of phishing emails have been distributed via the Phorpiex botnet as part of a large-scale LockBit Black ransomware campaign. The New Jersey Cybersecurity and Communications Integration Cell (NJCCIC) recently warned about this ongoing threat. Attackers are using ZIP attachments containing executables that deploy the LockBit Black payload, which encrypts recipients’ systems upon execution. This campaign leverages the LockBit 3.0 builder, which was leaked in 2022, although it is not directly affiliated with the original LockBit ransomware group.

Phishing emails in this campaign often use subject lines like “your document” and “photo of you???” and are sent from aliases such as “Jenny Brown” or “Jenny Green.” These emails originate from over 1,500 unique IP addresses globally, including locations in Kazakhstan, Uzbekistan, Iran, Russia, and China. The attack chain begins when a recipient opens the malicious ZIP archive and executes the binary inside, leading to the download and execution of the LockBit Black ransomware from the Phorpiex botnet infrastructure. The ransomware then attempts to steal sensitive data, terminate services, and encrypt files on the victim’s system.

Proofpoint, a cybersecurity company, has been investigating these attacks since April 24. They reported observing millions of messages facilitated by the Phorpiex botnet, delivering LockBit Black ransomware in high volumes. This approach, while not new, is notable for the sheer scale of emails sent and the use of ransomware as the initial payload. The Phorpiex botnet, also known as Trik, has a long history of malicious activities, including spreading via USB storage and chat applications, delivering sextortion emails, and hijacking cryptocurrency transactions.

To defend against these phishing attacks, NJCCIC recommends implementing ransomware risk mitigation strategies, using endpoint security solutions, and deploying email filtering solutions like spam filters to block potentially malicious messages. Staying vigilant and updating security measures are crucial in mitigating the risks posed by this widespread campaign.

Reference:

  • Millions of Emails Spread LockBit Black Ransomware Through Phorpiex Botnet

Tags: BotnetsCyber AlertCyber Alerts 2024Cyber RiskCyber threatLockBitMay 2024New JerseyPhorpiex botnet
ADVERTISEMENT

Related Posts

Fileless Remcos RAT Delivery Via LNK Files

APT28 RoundPress Webmail Hack Steals Emails

May 16, 2025
Fileless Remcos RAT Delivery Via LNK Files

FBI Warns of AI Voice Phishing Scams

May 16, 2025
Fileless Remcos RAT Delivery Via LNK Files

Fileless Remcos RAT Delivery Via LNK Files

May 16, 2025
HTTPBot DDoS Threat To Windows Systems

Horabot Malware Targets LatAm Via Phishing

May 15, 2025
HTTPBot DDoS Threat To Windows Systems

Google Patches Chrome Account Takeover Bug

May 15, 2025
HTTPBot DDoS Threat To Windows Systems

HTTPBot DDoS Threat To Windows Systems

May 15, 2025

Latest Alerts

Fileless Remcos RAT Delivery Via LNK Files

FBI Warns of AI Voice Phishing Scams

APT28 RoundPress Webmail Hack Steals Emails

Google Patches Chrome Account Takeover Bug

Horabot Malware Targets LatAm Via Phishing

HTTPBot DDoS Threat To Windows Systems

Subscribe to our newsletter

    Latest Incidents

    Hackers Target Swiss Reserve Power Plant

    Coinbase Insider Attack Exposed User Data

    Cyberattack Hits J Batista Group

    Dior Breach Exposes Asian Customer Data

    Australian Human Rights Body Files Leaked

    Nucor Cyberattack Halts Plants Networks

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial