LockFile attacks have been recorded mostly in the U.S. and Asia, its victims in the following sectors: financial services, manufacturing, travel, engineering, legal, business services, and tourism. Security researchers at Symantec, a division of Broadcom, said that the actors initial access on the network is through Microsoft Exchange servers. At this point, the official mitigations and updates do not completely block the PetitPotam attack vector. At least on ransomware threat actor has started to leverage the recently discovered Petit potam NTLM attack method to take over the Windows domain on various networks worldwide.”]