Threat reportThreat IntelligenceTL-2026-1121

La Trobe University research: network-based detection of SMB shared-storage ransomware encryption

MONITORING

La Trobe University research (TL-2026-1121) is a info-severity tracked intrusion set, first published 2026-07-05. It is linked to a Russia-nexus actor with medium confidence, maps to 21 MITRE ATT&CK techniques (T1003.001, T1021.001, T1027), and is covered by 9 detection rules and 24 indicators of compromise.

Severity
INFOAssessed severity
CVEs
0None referenced
Techniques
21MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
24Indicators of compromise

Key facts for TL-2026-1121

Threat ID
TL-2026-1121
Severity
INFO
Status
MONITORING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government administration, finance, health, manufacturing, education, energy, transport, foodandagriculture
Target regions
North America, Europe, australia, Global
Detection rules
9
Indicators of compromise
24

Malware and tooling in La Trobe University research

Malware and tooling: LockBit, LockBit 3.0 - S1202, 7-Zip, Chocolatey, Cobalt Strike, FakeUpdates, FileZilla, Hicrypt, MEGA, ProDump, PuTTY Link (Plink), Random Committee classifier

How La Trobe University research works

Academic researchers at La Trobe University (Melbourne, Australia) published a network-wire detection framework — SMBv2 packet-size 'Region of Interest' signatures feeding a three-stage classifier culminating in a Random Committee machine-learning model — that identifies ransomware bulk-encrypting files on SMB-based shared network storage with ~99.6% accuracy in testing. LockBit, a globally active, financially motivated Ransomware-as-a-Service (RaaS) operation tracked by CISA since 2020 and disrupted (but not eliminated) by the February 2024 'Operation Cronos' law-enforcement action, was used only as one illustrative test sample and was identified by the framework after roughly one-third of its encryption run had completed. The research itself discloses no new CVE, exploited vulnerability, malware sample, or C2 infrastructure; this record documents the detection methodology plus independently sourced background on the illustrative ransomware family so defenders have context for the reference.

La Trobe University researchers developed a network-wire detection framework for ransomware that bulk-encrypts files on SMB-based shared network storage. The method does not inspect file contents; it fingerprints SMB control-plane behavior. It first identifies a 'Region of Interest' by tracking directory/file-enumeration packets that hold a consistent size (~260 bytes on SMBv2), then examines control packets that stay a fixed size for specific SMB operations (e.g., ~410 bytes for new-file-creation responses); everything between two boundary packets becomes one unit of activity, removing bias introduced by fixed time-window analysis. Classification runs in three stages: (1) comparison against known indicators of compromise, (2) ransom-note size fingerprinting (each ransomware family tends to produce a recognizable note size), and (3) a Random Committee ensemble machine-learning classifier trained on the resulting packet-size feature set. Reported performance was ~99.6% accuracy on the researchers' test dataset with zero false negatives and a low false-positive rate; an early-detection variant tuned to trigger on minimal observed activity reported ~99.44% accuracy. Testing used a single-client/single-server testbed, and to stress benign-vs-malicious discrimination the researchers generated legitimate-but-attack-like traffic using Hicrypt, TeraCopy bulk file-copy operations, and WinRAR/7-Zip with encryption enabled, alongside real ransomware samples. LockBit was one of the ransomware samples used in testing and became identifiable by the framework after roughly one-third of its encryption run; encrypted SMBv3 traffic was evaluated as a separate dataset not detailed in the primary write-up, and the paper does not address production-network scalability beyond the single-testbed setup. The preprint is hosted at arxiv.org/abs/2606.30586.

This is a defensive detection-methodology publication, not an active-threat report: it discloses no CVE, no CVSS-scored vulnerability, no exploited flaw, no new ransomware variant or campaign, no C2 infrastructure, and no malware sample/hash of its own. It was surfaced by the HUNT phase and explicitly marked SKIP ('Does not meet HUNT threat-selection criteria: no CVE, no CVSS, no confirmed active exploitation, no public exploit PoC, no CISA KEV listing, no nation-state attribution/new TTPs, no supply-chain compromise, and no new ransomware variant or campaign'); independent WebFetch verification of the Help Net Security article confirms that determination.

Because the source article names LockBit specifically as its illustrative ransomware sample, this record documents LockBit's independently sourced background as threat-intelligence context for defenders evaluating the detection approach. LockBit was first observed in September 2019 operating under the '.abcd' file extension (tracked by some vendors as ABCD Ransomware), rebranded to LockBit and adopted a Ransomware-as-a-Service affiliate model in 2020, released LockBit 2.0 in July 2021 (adding Active Directory group-policy abuse to auto-encrypt Windows domains), and released LockBit 3.0 / LockBit Black in June 2022 (adding anti-analysis techniques, password-gated execution, and a ransomware bug-bounty program). CrowdStrike tracks the operator as BITWISE SPIDER; other vendors use the aliases Syrphid and Water Selkie. Per CISA/FBI/MS-ISAC joint advisory AA23-165A (2023-06-14), LockBit was the most active global ransomware/RaaS operation by claimed-victim count in 2022, with affiliates attacking organizations across financial services, food and agriculture, education, energy, government/emergency services, healthcare, manufacturing, and transportation sectors since January 2020. CISA/FBI advisory AA23-075A (2023-03-16, 'StopRansomware: LockBit 3.0') documents affiliate tooling and MITRE ATT&CK-mapped TTPs including Cobalt Strike beacons, SoftPerfect Network Scanner, ProDump-based LSASS credential dumping, PuTTY Link (Plink) tunneling, rclone/MEGA/FileZilla-based exfiltration, and Chocolatey-based tool deployment. A follow-on advisory, AA23-325A (2023-11-21), documented LockBit 3.0 affiliates actively exploiting CVE-2023-4966 ('Citrix Bleed', in Citrix NetScaler ADC/Gateway appliances) for initial access — including the confirmed breach of Boeing Distribution Inc. — with some intrusions additionally leveraging CVE-2020-1472 ('Zerologon') for rapid privilege escalation to Domain Admin via tools such as Invoke-ZeroLogon.ps1/SharpZeroLogon. On 2024-02-19/20, the NCA-, FBI-, and Europol-led international task force 'Operation Cronos' seized LockBit's primary data-leak-site infrastructure and 34 servers across the Netherlands, Germany, Finland, France, Switzerland, Australia, the US, and the UK, recovered 1,000+ victim decryption keys, indicted Russian nationals, and froze 200+ associated cryptocurrency accounts. LockBit affiliate nationality in these indictments is Russian, though LockBit is a financially motivated criminal RaaS operation, not a confirmed state-sponsored actor. Despite Operation Cronos, LockBit has resurged: it formed a strategic alliance with the Qilin and DragonForce ransomware operations around October 2025, and LockBit 5.0 ranked as the fourth most active ransomware operation in Q1 2026 with 163 recorded victims — underscoring continued relevance of network-based SMB detection research such as the La Trobe University framework documented in this record.

Net assessment: no new vulnerability, exploit, malware sample, or campaign is being reported here. The record exists to catalog a promising defensive detection technique and to give analysts sourced, verifiable background on the one ransomware family the researchers used to illustrate it.

MITRE ATT&CK techniques used in TL-2026-1121

Credential Access

T1003.001 LSASS Memory

Lateral Movement

T1021.001 Remote Desktop Protocol

Defense Evasion

T1027 Obfuscated Files or Information; T1070.004 File Deletion; T1480.001 Environmental Keying

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery; T1614.001 System Language Discovery

Command and Control

T1071.002 File Transfer Protocols; T1572 Protocol Tunneling

Execution

T1072 Software Deployment Tools

Initial Access

T1078 Valid Accounts; T1133 External Remote Services; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566 Phishing

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

Persistence

T1547 Boot or Logon Autostart Execution

Privilege Escalation

T1547 Boot or Logon Autostart Execution

Exfiltration

T1567 Exfiltration Over Web Service

Remediation for La Trobe University research

Patches

  • Apply vendor patches for CVE-2023-4966 (Citrix Bleed) on all Citrix NetScaler ADC/Gateway appliances.
  • Apply Microsoft patches for CVE-2020-1472 (Zerologon) on all Windows domain controllers.

Immediate actions

  • No direct remediation is required from this record alone — it discloses no new vulnerability, exploit, or active campaign; treat it as background threat-intelligence context for a defensive detection technique.
  • Maintain standard LockBit-related hardening: ensure internet-facing Citrix NetScaler ADC/Gateway appliances are patched against CVE-2023-4966 (Citrix Bleed) and domain controllers are patched against CVE-2020-1472 (Zerologon), both historically exploited by LockBit affiliates for initial access and privilege escalation respectively.
  • Restrict, log, and monitor SMBv1/v2/v3 traffic to shared network storage; disable SMBv1 where still enabled.

Workarounds

  • Where patching is delayed, force session-token invalidation and re-authentication with MFA on Citrix NetScaler appliances to reduce Citrix Bleed session-hijack exposure.
  • Enable SMB signing and disable legacy SMBv1 to reduce viable lateral-movement paths onto shared storage.

Longer-term hardening

  • Evaluate network-based SMB traffic analytics (packet-size / Region-of-Interest signature detection plus Random Committee ML classification) as a complementary control to endpoint EDR/DFIR tooling for detecting bulk file-encryption behavior against shared network storage.
  • Continue monitoring academic literature (arXiv:2606.30586) for maturation of this detection technique toward production tooling and multi-client/multi-server scalability validation beyond the single-testbed study.
  • Maintain detection coverage for LockBit's post-Operation-Cronos resurgence (LockBit 5.0, Qilin/DragonForce alliance) given continued victim activity reported in Q1 2026.

Timeline of La Trobe University research

  • LockBit ransomware first observed in the wild, initially operating under the '.abcd' file extension (tracked by some vendors as ABCD Ransomware) before adopting the LockBit brand.
  • The operation rebrands from ABCD to LockBit and adopts a Ransomware-as-a-Service (RaaS) affiliate model; CISA reports affiliate attacks beginning this year across multiple critical-infrastructure sectors.
  • LockBit 2.0 officially released, adding the ability to abuse Active Directory group policy to automatically encrypt Windows domains.
  • LockBit 3.0 (LockBit Black) launched, adding anti-analysis techniques, password-gated execution, command-line augmentation, and the first ransomware bug-bounty program.
  • CISA/FBI publish joint advisory AA23-075A ('#StopRansomware: LockBit 3.0'), detailing affiliate tooling (Cobalt Strike, SoftPerfect Network Scanner, ProDump, rclone, MEGA, FileZilla, Plink, Chocolatey) and MITRE ATT&CK-mapped TTPs.
  • CISA/FBI/MS-ISAC publish joint advisory AA23-165A, 'Understanding Ransomware Threat Actors: LockBit,' documenting LockBit as the most active global ransomware/RaaS operation by claimed-victim count in 2022.
  • CISA/FBI advisory AA23-325A warns that LockBit 3.0 affiliates are actively exploiting CVE-2023-4966 (Citrix Bleed) for initial access, including the confirmed breach of Boeing Distribution Inc.; some intrusions additionally leveraged CVE-2020-1472 (Zerologon) for privilege escalation.
  • International task force 'Operation Cronos' (NCA, FBI, Europol, and partners) seizes LockBit's primary data-leak-site infrastructure and 34 servers across the Netherlands, Germany, Finland, France, Switzerland, Australia, the US, and the UK.
  • Operation Cronos publicly announced; law enforcement releases 1,000+ recovered decryption keys, indicts Russian nationals, and freezes 200+ cryptocurrency accounts linked to the group.
  • LockBit forms a strategic alliance with the Qilin and DragonForce ransomware operations, signaling resurgence following the Operation Cronos disruption.
  • Industry reporting places LockBit 5.0 as the fourth most active ransomware operation in Q1 2026, with 163 recorded victims despite the 2024 law-enforcement takedown.
  • Help Net Security publishes coverage of La Trobe University's SMB shared-storage ransomware detection research, which cites LockBit as an illustrative test sample identified by the framework after roughly one-third of its encryption run.

Sources cited for La Trobe University research

Detection coverage for TL-2026-1121

As of 2026-07-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1121 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
24 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats