In this Twitch stream we take a look at the recently leaked LockBit Ransomware Builder. We compare our previous RE analysis of the ransomware binary with the actual builder config (some surprises, but we were mostly correct). And we take a look the possibility of the building being used by individual unaffiliated Threat Actors (TA) to start their own ransomware campaigns.
We aren't going to link to the leaks for reasons that will become apparent by the end of the stream, but you can google for it.