SecurityScorecard reported network and malware evidence consistent with a LockBit ransomware intrusion at a major state-owned bank in Southeast Asia after the group listed the organization on its leak site. Researchers observed indicators of possible credential theft, remote access over SSH and RDP, and large outbound data transfers before and after the public extortion claim, suggesting potential data exfiltration as part of the operation. The activity was linked to several IP addresses tied to malicious infrastructure, anonymizing VPN or proxy services, and a Russian IP address that may have accessed intermediary systems.
The reported intrusion aligns with known LockBit 3.0 capabilities documented by VMware, which described a highly configurable ransomware strain able to generate new variants from a leaked builder and target local systems, network shares, connected drives, and domain controllers. VMware said the malware uses anti-analysis techniques, privilege escalation, service termination, shadow-copy deletion, ransom-note deployment, and Salsa20 file encryption, while communicating with command-and-control infrastructure over TLS 1.2 using HTTP POST requests. The leaked builder and flexible configuration likely lowered the barrier for affiliates and helped sustain LockBit’s broad operational reach against enterprise victims.

TTPs, infrastructure, and targeting history in one profile.
15 events from the most recent confirmed update back to the earliest known activity.
On March 9, a bank-attributed IP address communicated 189 times over port 25 with 46.255.225[.]8 in Czechia. SecurityScorecard notes two malicious files previously seen exfiltrating data via SMTP had communicated with that IP and assesses this may reflect an early-stage compromise.
SecurityScorecard reports that a bank mail server with port 22 open communicated throughout March with 170.210.208[.]108, an IP linked by Attack Surface Intelligence to SSH brute-force attacks. The report says the traffic sample reflected attempts to access a bank server via SSH and a possible malware infection beginning in March.
SecurityScorecard cites a March 2023 CISA alert describing LockBit initial access methods such as RDP compromise, phishing, valid account abuse, and exploitation of public-facing applications, along with use of Stealbit and web services for exfiltration.
VMware says that in September 2022 a LockBit 3.0 builder was reported leaked on Twitter by @3xp0rtblog, attributed to @ali_qushji, and made available on GitHub. The leak enabled detailed reverse engineering and could lower the barrier for other actors to create variants.
VMware reports that in July 2022 LockBit 3.0 publicly said it would publish data from nonpaying victims in a searchable online form and introduced a bug bounty program for its ransomware.
SecurityScorecard says the group rebranded again in spring 2022 as LockBit 3.0, also known as LockBit Black.
SecurityScorecard reports that the group rebranded as LockBit 2.0 in January 2021.
SecurityScorecard states that LockBit has operated as a ransomware-as-a-service group since 2019.
SecurityScorecard says additional NetFlow data covering May 8 to May 12 revealed eight flows of 100 MB or more involving additional U.S.-based cloud service IP addresses. The report presents this as further evidence consistent with exfiltration activity around the claimed intrusion.
SecurityScorecard reports that LockBit publicly claimed an attack against a major state-owned bank in Southeast Asia on May 8.
Between May 1 and May 6, SecurityScorecard observed 17 transfers larger than 10 MB totaling about 11.71 GB between three bank-attributed IP addresses and nine non-bank IP addresses. Eight of the nine external IPs were assessed as high-risk U.S.-based commercial servers that could proxy malicious traffic.
On April 30, a bank-attributed IP address hosting an Imperva WAF communicated with 70.39.90[.]165. SecurityScorecard says an anti-fraud service identified that external IP as an anonymizing VPN address.
On April 27 at 04:00:20 UTC, 46.101.164[.]225 contacted a bank-attributed IP hosting an Imperva web application firewall over port 3389. Researchers assessed the traffic could indicate RDP-based access to the bank environment.
On April 19, a bank IP address communicated 70 times with 23.253.253[.]26 and exchanged about 26.36 GB of data. SecurityScorecard assessed the transfer may indicate data exfiltration and noted the IP had prior links to malicious or suspicious activity.
SecurityScorecard says two files first appearing on April 10 and April 12 contained a bank subdomain and were detected in VirusTotal as SpyNote or SpyMax malware. Researchers assessed the samples likely impersonated the victim bank’s mobile banking application to steal credentials and 2FA codes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 43 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.