Monday, September 15, 2025
Google search engine
HomeTechnologyCyber SecurityLockBit ransomware gang hacked, sufferer negotiations uncovered

LockBit ransomware gang hacked, sufferer negotiations uncovered


The LockBit ransomware gang has suffered an information breach after its darkish internet affiliate panels have been defaced and changed with a message linking to a MySQL database dump.

The entire ransomware gang’s admin panels now state. “Do not do crime CRIME IS BAD xoxo from Prague,” with a hyperlink to obtain a “paneldb_dump.zip.”

LockBit dark web site defaced with link to databaseLockBit darkish site defaced with hyperlink to database

As first noticed by the risk actor, Rey, this archive incorporates a SQL file dumped from the positioning affiliate panel’s MySQL database.

From evaluation by BleepingComputer, this database incorporates twenty tables, with some extra attention-grabbing than others, together with:

A ‘btc_addresses’ desk that incorporates 59,975 distinctive bitcoin addresses.
A ‘builds’ desk incorporates the person builds created by associates for assaults. Desk rows include the general public keys, however no non-public keys, sadly. The focused corporations’ names are additionally listed for a number of the builds.
A ‘builds_configurations’ desk incorporates the completely different configurations used for every construct, resembling which ESXi servers to skip or recordsdata to encrypt.
A ‘chats’ desk may be very attention-grabbing because it incorporates 4,442 negotiation messages between the ransomware operation and victims from December nineteenth to April twenty ninth.

Affiliate panel 'chats' tableAffiliate panel ‘chats’ desk

A ‘customers’ desk lists 75 admins and associates who had entry to the affiliate panel, with Michael Gillespie recognizing that passwords have been saved in plaintext. Examples of a number of the plaintext passwords are ‘Weekendlover69, ‘MovingBricks69420’, and ‘Lockbitproud231’.

In a Tox dialog with Reythe LockBit operator referred to as ‘LockBitSupp’ confirmed the breach, stating that no non-public keys have been leaked or information misplaced.

Primarily based on the MySQL dump technology time and the final date file within the negotiation chats desk , the database seems to have been dumped sooner or later on April twenty ninth, 2025.

It is unclear who carried out the breach and the way it was finished, however the defacement message matches the one utilized in a latest breach of Everest ransomware’s darkish site, suggesting a doable hyperlink.

Moreover, the phpMyAdmin SQL dump exhibits that the server was operating PHP 8.1.2, which is susceptible to essential and actively exploited vulnerability tracked as CVE-2024-4577 that can be utilized to attain distant code execution on servers.

In 2024, a regulation enforcement operation referred to as Operation Cronos took down LockBit’s infrastructure, together with 34 servers internet hosting the information leak web site and its mirrors, information stolen from the victims, cryptocurrency addresses, 1,000 decryption keys, and the affiliate panel.

Though LockBit managed to rebuild and resume operations after the takedown, this newest breach strikes an extra blow to its already broken fame.

It is too early to inform if this extra fame hit would be the closing nail within the coffin for the ransomware gang.

Different ransomware teams who’ve skilled comparable leaks embrace Conti, Black Basta, and Everest.


Red Report 2025

Primarily based on an evaluation of 14M malicious actions, uncover the highest 10 MITRE ATT&CK methods behind 93% of assaults and the right way to defend towards them.

Learn the Purple Report 2025



Supply hyperlink

RELATED ARTICLES

1 COMMENT

  1. Looks like my earlier comment didn’t appear, but I just wanted to say—your blog is so inspiring! I’m still figuring things out as a beginner,and reading your posts makes me want to keep going with my own writing journey.

Leave a Reply to 카드깡 Cancel reply

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments