# La Trobe University research: network-based detection of SMB shared-storage ransomware encryption

> Academic researchers at La Trobe University (Melbourne, Australia) published a network-wire detection framework — SMBv2 packet-size 'Region of Interest' signatures feeding a three-stage classifier culminating in a Random Committee machine-learning model — that identifies ransomware bulk-encrypting files on SMB-based shared network storage with ~99.6% accuracy in testing. LockBit, a globally active, financially motivated Ransomware-as-a-Service (RaaS) operation tracked by CISA since 2020 and disrupted (but not eliminated) by the February 2024 'Operation Cronos' law-enforcement action, was used only as one illustrative test sample and was identified by the framework after roughly one-third of its encryption run had completed. The research itself discloses no new CVE, exploited vulnerability, malware sample, or C2 infrastructure; this record documents the detection methodology plus independently sourced background on the illustrative ransomware family so defenders have context for the reference.

- **Published:** 2026-07-05T00:00:00Z
- **Last reviewed:** 2026-07-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1121
- **ID:** TL-2026-1121
- **Severity:** INFO
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

La Trobe University researchers developed a network-wire detection framework for ransomware that bulk-encrypts files on SMB-based shared network storage. The method does not inspect file contents; it fingerprints SMB control-plane behavior. It first identifies a 'Region of Interest' by tracking directory/file-enumeration packets that hold a consistent size (~260 bytes on SMBv2), then examines control packets that stay a fixed size for specific SMB operations (e.g., ~410 bytes for new-file-creation responses); everything between two boundary packets becomes one unit of activity, removing bias introduced by fixed time-window analysis. Classification runs in three stages: (1) comparison against known indicators of compromise, (2) ransom-note size fingerprinting (each ransomware family tends to produce a recognizable note size), and (3) a Random Committee ensemble machine-learning classifier trained on the resulting packet-size feature set. Reported performance was ~99.6% accuracy on the researchers' test dataset with zero false negatives and a low false-positive rate; an early-detection variant tuned to trigger on minimal observed activity reported ~99.44% accuracy. Testing used a single-client/single-server testbed, and to stress benign-vs-malicious discrimination the researchers generated legitimate-but-attack-like traffic using Hicrypt, TeraCopy bulk file-copy operations, and WinRAR/7-Zip with encryption enabled, alongside real ransomware samples. LockBit was one of the ransomware samples used in testing and became identifiable by the framework after roughly one-third of its encryption run; encrypted SMBv3 traffic was evaluated as a separate dataset not detailed in the primary write-up, and the paper does not address production-network scalability beyond the single-testbed setup. The preprint is hosted at arxiv.org/abs/2606.30586.

This is a defensive detection-methodology publication, not an active-threat report: it discloses no CVE, no CVSS-scored vulnerability, no exploited flaw, no new ransomware variant or campaign, no C2 infrastructure, and no malware sample/hash of its own. It was surfaced by the HUNT phase and explicitly marked SKIP ('Does not meet HUNT threat-selection criteria: no CVE, no CVSS, no confirmed active exploitation, no public exploit PoC, no CISA KEV listing, no nation-state attribution/new TTPs, no supply-chain compromise, and no new ransomware variant or campaign'); independent WebFetch verification of the Help Net Security article confirms that determination.

Because the source article names LockBit specifically as its illustrative ransomware sample, this record documents LockBit's independently sourced background as threat-intelligence context for defenders evaluating the detection approach. LockBit was first observed in September 2019 operating under the '.abcd' file extension (tracked by some vendors as ABCD Ransomware), rebranded to LockBit and adopted a Ransomware-as-a-Service affiliate model in 2020, released LockBit 2.0 in July 2021 (adding Active Directory group-policy abuse to auto-encrypt Windows domains), and released LockBit 3.0 / LockBit Black in June 2022 (adding anti-analysis techniques, password-gated execution, and a ransomware bug-bounty program). CrowdStrike tracks the operator as BITWISE SPIDER; other vendors use the aliases Syrphid and Water Selkie. Per CISA/FBI/MS-ISAC joint advisory AA23-165A (2023-06-14), LockBit was the most active global ransomware/RaaS operation by claimed-victim count in 2022, with affiliates attacking organizations across financial services, food and agriculture, education, energy, government/emergency services, healthcare, manufacturing, and transportation sectors since January 2020. CISA/FBI advisory AA23-075A (2023-03-16, 'StopRansomware: LockBit 3.0') documents affiliate tooling and MITRE ATT&CK-mapped TTPs including Cobalt Strike beacons, SoftPerfect Network Scanner, ProDump-based LSASS credential dumping, PuTTY Link (Plink) tunneling, rclone/MEGA/FileZilla-based exfiltration, and Chocolatey-based tool deployment. A follow-on advisory, AA23-325A (2023-11-21), documented LockBit 3.0 affiliates actively exploiting CVE-2023-4966 ('Citrix Bleed', in Citrix NetScaler ADC/Gateway appliances) for initial access — including the confirmed breach of Boeing Distribution Inc. — with some intrusions additionally leveraging CVE-2020-1472 ('Zerologon') for rapid privilege escalation to Domain Admin via tools such as Invoke-ZeroLogon.ps1/SharpZeroLogon. On 2024-02-19/20, the NCA-, FBI-, and Europol-led international task force 'Operation Cronos' seized LockBit's primary data-leak-site infrastructure and 34 servers across the Netherlands, Germany, Finland, France, Switzerland, Australia, the US, and the UK, recovered 1,000+ victim decryption keys, indicted Russian nationals, and froze 200+ associated cryptocurrency accounts. LockBit affiliate nationality in these indictments is Russian, though LockBit is a financially motivated criminal RaaS operation, not a confirmed state-sponsored actor. Despite Operation Cronos, LockBit has resurged: it formed a strategic alliance with the Qilin and DragonForce ransomware operations around October 2025, and LockBit 5.0 ranked as the fourth most active ransomware operation in Q1 2026 with 163 recorded victims — underscoring continued relevance of network-based SMB detection research such as the La Trobe University framework documented in this record.

Net assessment: no new vulnerability, exploit, malware sample, or campaign is being reported here. The record exists to catalog a promising defensive detection technique and to give analysts sourced, verifiable background on the one ransomware family the researchers used to illustrate it.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1133 External Remote Services
- T1189 Drive-by Compromise
- T1566 Phishing
- T1190 Exploit Public-Facing Application
- T1072 Software Deployment Tools
- T1547 Boot or Logon Autostart Execution
- T1547 Boot or Logon Autostart Execution
- T1027 Obfuscated Files or Information
- T1070.004 File Deletion
- T1480.001 Environmental Keying
- T1003.001 LSASS Memory
- T1046 Network Service Discovery
- T1082 System Information Discovery
- T1614.001 System Language Discovery
- T1021.001 Remote Desktop Protocol
- T1071.002 File Transfer Protocols
- T1572 Protocol Tunneling
- T1567 Exfiltration Over Web Service
- T1485 Data Destruction
- T1490 Inhibit System Recovery
- T1486 Data Encrypted for Impact

## Sources

- [New detection method could help stop ransomware in shared storage systems](https://www.helpnetsecurity.com/2026/07/02/shared-storage-ransomware-detection-research/)
- [Region-of-Interest SMB ransomware detection preprint (La Trobe University)](https://arxiv.org/abs/2606.30586)
- [CISA AA23-165A: Understanding Ransomware Threat Actors: LockBit](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a)
- [CISA AA23-075A: #StopRansomware: LockBit 3.0](https://www.cisa.gov/sites/default/files/2023-03/aa23-075a-stop-ransomware-lockbit.pdf)
- [CISA AA23-325A: LockBit 3.0 Ransomware Affiliates Exploit CVE-2023-4966 Citrix Bleed Vulnerability](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a)
- [CISA Alert AA23-075A: The Latest LockBit Ransomware Variant - LockBit 3.0 (TTP/IOC analysis)](https://www.picussecurity.com/resource/blog/cisa-alert-aa23-075a-the-latest-lockbit-ransomware-variant-lockbit-3.0)
- [LockBit 3.0, Software S1202](https://attack.mitre.org/software/S1202/)
- [A Timeline of Events: Operation Cronos and LockBit](https://slcyber.io/a-timeline-of-events-operation-cronos-and-lockbit/)
- [LockBit Ransomware Operation Shut Down; Criminals Arrested; Decryption Keys Released](https://thehackernews.com/2024/02/lockbit-ransomware-operation-shut-down.html)
- [Unveiling the Fallout: Operation Cronos' Impact on LockBit Following Landmark Disruption](https://www.trendmicro.com/en_us/research/24/d/operation-cronos-aftermath.html)
- [LockBit Ransomware: Attack Methods and 2026 Status](https://cybelangel.com/blog/lockbit-cybercriminal-guide/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1121
