LockBit 3.0 Ransomware: 72-Hour Containment, Zero Ransom Paid

A mid-size precision parts manufacturer discovered a LockBit 3.0 infection spreading across their production network at 11 PM on a Sunday. eNeoteric's IR team was on-site within 6 hours. Full containment in 72 hours. Full recovery from backup in 96 hours. No ransom paid.

72 hours
Time to full containment
240
Endpoints affected
₹0
Ransom paid
6 hrs
CERT-In notification filed within

The Incident

The attacker had been present in the network for an estimated 23 days (based on the earliest evidence of lateral movement in SIEM logs). Initial access was via a phishing email that delivered a malicious macro to the accounts payable team. The attacker moved laterally using valid credentials harvested from an unpatched domain controller.

At the point of discovery, LockBit 3.0 ransomware was active on 240 Windows endpoints, 6 file servers, and 2 domain controllers. The production PLC network was isolated by a poorly configured firewall that — fortunately — had not been traversed by the attacker.

Our Response

  • Hour 0–6: eNeoteric IR team deployed on-site. Network isolation of affected VLANs. Preserved evidence on 12 priority systems (memory dumps, forensic disk images). CERT-In notification drafted and submitted within 6-hour mandate.
  • Hour 6–24: Attacker TTPs identified (initial access vector, C2 channels, lateral movement path, persistence mechanisms). All 4 C2 domains and IP ranges blocked at perimeter. 8 compromised accounts reset. Backups verified clean (last clean backup: 48 hours prior).
  • Hour 24–72: Clean rebuild of 240 endpoints using SCCM with patched base image. Domain controllers rebuilt from known-clean backup. All systems hardened before return to production (SMBv1 disabled, LSASS protection enabled, privileged access workstations configured).
  • Hour 72–96: Production systems restored. WMS and ERP validated by operations team. Manufacturing lines resumed.

Root Cause & Lessons

  • Initial access: phishing email with malicious Excel macro — no email sandboxing in place
  • Lateral movement enabled by domain admin credentials stored in LSASS memory on a shared workstation
  • Dwell time extended by absence of SIEM / EDR — no alert generated for 23 days
  • Backup integrity confirmed — immutable backup policy saved the client from ransom demand

Post-incident, eNeoteric deployed an EDR solution across all endpoints, enabled email sandboxing, and configured privileged identity management to prevent credential theft via LSASS.

Outcomes & Impact

Manufacturing operations resumed 96 hours after incident discovery — against a projected 15-day recovery timeline if the client had relied solely on internal IT resources. The immutable backup strategy prevented any ransom negotiation, saving an estimated ₹85 lakhs based on the attacker's ransom note.

The CERT-In notification was accepted as compliant with the 6-hour mandate. Post-incident, the client engaged eNeoteric for a 12-month managed SOC contract and a full VAPT of their recovered environment.

“We called eNeoteric at 11:30 PM on a Sunday. By 6 AM there were engineers on-site. That response speed made the difference between a 4-day and a 4-week outage.”
IT DirectorPrecision Parts Manufacturer, Pune

Related services

← All Case Studies Discuss your use case →

Request a Callback

Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.

💬 Chat on WhatsApp instead
Chat on WhatsApp