Researchers reported that multiple ransomware families, including DoNex, BabLock/Rorschach, and LockBit Black (v3), share substantial code and operational overlap with LockBit, underscoring how leaked builder code and recycled components continue to fuel new strains. SANS assessed DoNex as an unoriginal LockBit-derived operation closely resembling Darkrace, with behavior including process and service termination, network-share enumeration, event-log clearing, ransom-note deployment, and forced reboot after encryption. Trend Micro similarly found that BabLock appears heavily based on LockBit 2.0 while incorporating features from other families, using DLL sideloading, Direct SysCalls, VMProtect, and unusual random numeric file extensions. Separate reverse engineering of LockBit v3 identified serious implementation flaws, including a keystream reuse bug and a design issue that could cause permanent data corruption, enabling partial decryption in some cases via an open-source decryptor.
Operational reporting also showed LockBit affiliates continuing to refine delivery and post-exploitation methods. ASEC documented phishing emails posing as copyright claims that delivered LockBit through nested password-protected archives and a fake PDF executable, after which the malware deleted shadow copies, altered boot recovery settings, established persistence, and encrypted files with the .lockbit extension. SentinelOne described a LockBit-linked intrusion that began with Log4Shell exploitation against an unpatched VMware Horizon server and progressed to abuse of legitimate Microsoft Defender tooling for DLL sideloading of Cobalt Strike, alongside PowerShell execution, web-shell deployment, and other living-off-the-land techniques. Together with earlier DarkSide analysis showing similar use of Salsa20/RSA, service killing, shadow-copy deletion, and network-resource encryption, the reports show a ransomware ecosystem in which LockBit code, cryptography, and tradecraft are repeatedly repackaged into new campaigns and variants.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Calif analyzed a LockBit v3/LockBit Black variant built from the leaked builder, identified a keystream-reuse crypto bug and a design flaw that can cause permanent corruption, and published an open-source decryptor. The report also noted newer variants in the wild no longer allowed exploitation of the crypto bug.
A SANS Internet Storm Center analysis concluded that DoNex is an unoriginal ransomware operation derived from leaked LockBit builder code and closely resembling the earlier Darkrace ransomware. The write-up documented its encryption workflow, service and process disruption, network-share encryption, and forced reboot behavior.
The SANS analysis states that Darkrace appeared in mid-June 2023 and closely resembled binaries produced from the leaked LockBit builder.
Trend Micro published an analysis of BabLock/Rorschach, describing its multi-component delivery, Direct SysCall use, VMProtect packing, unusual extension scheme, and use of tools such as Chisel and Fscan.
SentinelOne described a LockBit-attributed intrusion in which attackers exploited Log4j on an unpatched VMware Horizon Server, installed a web shell in Blast Secure Gateway, and used MpCmdRun.exe to sideload a malicious DLL that decrypted and loaded Cobalt Strike Beacon.
ASEC reported a phishing campaign distributing LockBit ransomware through emails disguised as copyright-claim messages, using nested compressed attachments and an executable masquerading as a PDF. The report also published malware behavior details and MD5 indicators.
Trend Micro said researchers discovered the BabLock ransomware family in June 2022 and later assessed it as a hybrid strain heavily based on LockBit 2.0 but distinct from core LockBit operators.
Trend Micro reported that the earliest records of BabLock (Rorschach)-related files it found were from March 2022, indicating the ransomware family was present by then.
A reverse-engineering analysis documented DarkSide ransomware version 1.8.6.2 for Windows, detailing its hybrid RSA-1024/Salsa20 cryptosystem, UAC bypass, shadow copy deletion, service and process killing, network-share encryption, and C2 reporting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
blog.calif.io
Open sourceisc.sans.edu
Open sourcetrendmicro.com
Open sourcesentinelone.com
Open sourceasec.ahnlab.com
Open sourcechuongdong.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.