BockLit
- First seen
- 2023-05-20 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 14:50:05
Targeted industries: technology-and-telecommunications financial-services healthcare-and-pharmaceutical
Context
According to Trend Micro, this is a ransomware written in Go, targeting Windows and MacOS environments that tries to disguise as LockBit by changing the wallpaper into a LockBit 2 screen. Most of the samples contained hard-coded AWS credentials, and the stolen data were uploaded to an Amazon S3 bucket controlled by the threat actor.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Bocklit (report)
- Trend Micro — Fake Lockbit Real Damage Ransomware Samples Abuse Aws S3 To Stea (report)