BockLit

First seen
2023-05-20 00:00:00
Malware type
ransomware
Profile updated
2026-07-07 14:50:05

Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Context

According to Trend Micro, this is a ransomware written in Go, targeting Windows and MacOS environments that tries to disguise as LockBit by changing the wallpaper into a LockBit 2 screen. Most of the samples contained hard-coded AWS credentials, and the stolen data were uploaded to an Amazon S3 bucket controlled by the threat actor.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Bocklit (report)
  • Trend Micro — Fake Lockbit Real Damage Ransomware Samples Abuse Aws S3 To Stea (report)

External references