Holated ranomware gang ransomware, revealed victim negotiations

Date:

Gang Ransomware Lockbit suffered a violation of information after its dark web -associated panels were defined and replaced by a message connecting with the screenshot of the MySQL database.

All ransomware administrative panels at the moment are consistent. “Don’t do crime The crime is bad XOXO from Prague, “with a link to download” paneludb_dump.zip “.

- Advertisement -
Lockbit Dark website with a database link
Lockbit Dark website with a database link

How First noticed By the actor, REY, the archive is included within the SQL file dropped from the MySQL database of the partner panel.

From BleepingComputer evaluation, this database incorporates twenty tables, with some more interesting than others, including:

  • A ‘Btc_addresses“Table containing 59,975 unique bitcoin addresses.
  • A ‘compilation“The table incorporates individual compilations created by associated entities for attacks. Table rows contain public keys, but unfortunately there aren’t any private keys. The names of the goal firms are also listed for some compilations.
  • A ‘configuration compilations“The table incorporates various configurations used for every compilation, akin to ESXI servers for skipping or encryption files.
  • A ‘conversations“The table could be very interesting since it incorporates 4442 negotiating messages between Ransomware and victims from December 19 to April 29.
    Table of
    Table of “Chats” of the Associated Panel
  • A ‘users“The table lists 75 administrators and associated entities who had access to the partner panel, from Michael Gillespie Noticing that the slogans were stored in a simple text. Examples of some ordinary text slogans are “Weekendlover69,” Movingbricks69420 “and” LockbitProud231 “.

IN Conversation with toxThe Lockbit Operator referred to as “LockbitSUPP” confirmed the violation, stating that no private keys were leaked or lost.

Based on the time to generate MySQL and the last date of the date within the negotiating chats table, the database seems in some unspecified time in the future dropped on April 29, 2025.

It will not be clear who carried out the violation and the way it was done, however the Defacement message matches the Everest Ransomware within the recent violation of the dark website, which is recommended by a possible link.

In addition, the SQL PHPMYADmin screenshot shows that the server has worked PHP 8.1.2, which is at risk of critical and actively used tracked susceptibility as CVE-2024-4577, which may be used to realize distant code on servers.

In 2024, the operation of law enforcement agencies called Cronos Operation removed the Lockbit infrastructure, including 34 servers hosting the information leakage website and its mirrors, data stolen from victims, cryptocurrency addresses, 1000 keys of decryption and affiliate panel.

Although Lockbit was in a position to rebuild and resume surgery after removal, this latest violation is an extra blow to the already damaged fame.

It is simply too early to find out whether this extra hit of fame shall be the last nail within the Ransomware gang.

Other ransomware groups which have experienced similar leaks are Conti, Black Basta and Everest.

Based on the evaluation of 14 -meter malicious activities, discover the ten best Att & CK techniques for 93% attacks and the way to defend against them.

Rome
Romehttps://globalcmd.com/
Rome: Visionary Founder of the GlobalCommand Ecosystem (GlobalCmd.com | GLCND.com | GlobalCmd A.I.) Rome is the innovative mind behind the GlobalCommand Ecosystem, a dynamic suite of platforms designed to revolutionize productivity for entrepreneurs, freelancers, small business owners, and forward-thinking individuals. Through his visionary leadership, Rome has developed tools and content that eliminate complexity, empower decision-making, and accelerate success. The Powerhouse of Productivity: GlobalCmd.com At the heart of Rome’s vision is GlobalCmd.com, an intuitive AI-powered platform designed to simplify decision-making and streamline workflows. Whether you’re solving complex business challenges, scaling a new idea, or optimizing daily operations, GlobalCmd.com transforms inputs into actionable, results-driven solutions. Rome’s approach is straightforward yet transformative: provide users with tools that deliver clarity, save time, and empower them to focus on growth and achievement. With GlobalCmd.com, users no longer have to navigate overwhelming tools or inefficient processes—Rome has redefined productivity for real-world needs. An Ecosystem Built for Excellence Rome’s vision extends far beyond productivity tools. The GlobalCommand Ecosystem includes platforms that address every step of the user’s journey: • GLCND.com: A professional blog and content hub offering expert insights and actionable advice across business, science, health, and more. GLCND.com inspires users to explore new ideas, sharpen their skills, and stay ahead in their fields. • GlobalCmd A.I.: The innovative AI engine powering GlobalCmd.com, designed to turn user inputs into tailored recommendations, predictive insights, and actionable strategies. Built on the cutting-edge RAD² Framework, this AI simplifies even the most complex decisions with precision and ease. The Why Behind GlobalCmd.com Rome understands the pressure and challenges of running a business, launching projects, and making impactful decisions in real time. His mission was to create a platform that eliminates unnecessary complexity and provides clear, practical solutions for users. Whether users are tackling new ventures, refining operations, or handling day-to-day decisions, Rome has designed the GlobalCommand Ecosystem to meet real-world needs with innovative, results-oriented tools. Empowering Success Through Simplicity Rome’s ultimate goal is to empower individuals with the right tools, insights, and strategies to take control of their work and achieve success. By combining the strengths of GlobalCmd.com, GLCND.com, and GlobalCmd A.I., Rome has created an ecosystem that transforms how people work, think, and grow. Start your journey to smarter decisions and greater success today. Visit GlobalCmd.com and take control of your future.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Our Newsletter

Subscribe Us To Receive Our Latest News Directly In Your Inbox!

We don’t spam! Read our privacy policy for more info.

Advertisement

Popular

More like this
Related

Harsh Goenka calls Pakistan “complete mismatch” against India: “It’s like Kohli vs Gully Cricketer”

Harsh Goenka, chairman of RPG Enterprises, called Pakistan again,...

Best stands for computer headphones 2025: The best types for audiophiles and players

Regardless of how much money it's essential to spend...

Challenges – and possibilities – the “golden dome” defense system

He swore on Tuesday to finish the construction of...