fastfire / deepdarkCTI

Collection of Cyber Threat Intelligence sources from the deep and dark web
GNU General Public License v3.0
4.04k stars 728 forks source link

Incorrect Tox ID for LockBitSupp #690

Open Casualtek opened 3 days ago

Casualtek commented 3 days ago

The Tox ID 3085... mentioned for LockBitSupp comes from LockBit Black samples made with the leaked builder: the ransom note for these samples also mention the old clear web domain name lockbitsupp[.]uz. Examples: c7e5e88d502152b82a708ef5d96f8fa6f7419f23 45ca493376d1d2b769a58bb4d98ce470a0567cd4

The Tox ID 3085... belongs to a TA without established affiliation with the LockBit 3.0 RaaS operation, that temporarily called himself Ikaruz Red Team: https://www.lemagit.fr/conseil/LockBit-30-des-independants-tres-divers