LockBit 2.0 is an affiliate-based Ransomware-as-a-Service (RaaS) that was first observed in June 2021. This chain simulates post-exploitation activity of LockBit, including deleting Volume Shadow Copies, performing a UAC bypass, creating a named pipe, and writing a ransom note to the user's desktop. Endpoint detection should identify LockBit 2.0 ransomware activity and respond before it can cause damage. This chain must be run as Administrator.
View Command
To view this TTPs command, you must be logged in with a professional or enterprise license.