SentinelOne Demo: SentinelOne VS LuckBit Ransomware – Detection and Mitigation
In this video demonstration, we show how the SentinelOne Singularity XDR Platform protects against LuckBit ransomware. LuckBit ransomware emerged in October of 2023. The threat actors behind LuckBit have been observed requesting payment in terms of equivalency to the Malaysian Ringgit (MYR), with campaigns observed requesting up to the equivalent of 20 Million MYR, paid in BTC (Bitcoin). This currently works out to approximately 158 BTC or $4.2 million.
Victims are instructed to only contact the attacker after making the requested ransom payment. The ransom note contains the relevant contact details including an email address and a TOR-based web site/victim portal. LuckBit payloads will attempt to inhibit system recovery by removing Volume Shadow Copies (VSS) via VSSADMIN.EXE. Infected systems are modified to display the ransom note upon every boot or startup.
The SentinelOne Singularity XDR Platform can return systems to their original state.
~Subscribe to our channels:~
Website: https://www.sentinelone.com/
LinkedIn: https://www.linkedin.com/company/sentinelone/
Twitter: https://twitter.com/SentinelOne
Facebook: https://www.facebook.com/SentinelOne
Instagram: https://www.instagram.com/sentinelsec/
Threads: https://www.threads.net/@sentinelsec