Axon Rapid Response - LockBit 3.0 Ransomware CISA AA23-325A
Incident Report for Rapid Response Status Page
Resolved
This incident has been resolved.
Posted Nov 23, 2023 - 12:42 UTC
Investigating
Following alert aa23-325a published by CISA, Team Axon has initiated a Rapid Response effort and investigated activities in Axon customers’ environments. The team delved into the activities linked to LockBit 3.0 affiliates and their post-exploitation actions subsequent to exploiting CVE-2023-4966, Citrix Bleed Vulnerability.
CISA Alert: https://www.cisa.gov//news-events/cybersecurity-advisories/aa23-325a.

As part of the Rapid Response efforts, the team conducted an IOC sweep over Axon customers’ environments based on the IOCs as provided in CISA's alert, which spans from the public disclosure of CVE-2023-4966 on Oct. 10, 2023.
Affected customers can access a comprehensive Axon report detailing relevant findings in their environment via the Hunters platform under the “Axon Reports” page.

As always, feel free to reach out for any assistance and further questions.

Team Axon.
Posted Nov 23, 2023 - 12:42 UTC
This incident affected: Rapid Response.