Skip to content
Malware family

LockBit

LockBit is a prolific cybercriminal ransomware-as-a-service operation that has been one of the most active and recognizable extortion threats globally since its emergence in 2019.

Profile source: Mallory opens in a new tab

LockBit

Family profile

LockBit is a prolific cybercriminal ransomware-as-a-service operation that has been one of the most active and recognizable extortion threats globally since its emergence in 2019. It operates through a core development and management team supported by affiliates who conduct intrusions, steal data, deploy ransomware, and negotiate extortion demands. The group is widely associated with double-extortion operations that combine file encryption with threats to publish stolen information, and it has repeatedly demonstrated the ability to rebrand, rebuild infrastructure, and continue operations after disruption.

LockBit is commonly referenced through multiple versioned and branding variants, including LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, and more recent references to LockBit 5.0. “LockBit Black” is broadly associated with the LockBit 3.0 generation. Reporting also frequently distinguishes the core operation from its affiliates, reflecting the group’s franchise-like operating model.

The operation has targeted organizations across a wide range of sectors and geographies, including manufacturing, government, healthcare, technology, retail, consulting, education, and critical services. Victimology has historically been heavily weighted toward the United States, but more recent reporting indicates broader international distribution, with sustained activity across Europe, Latin America, and Asia. LockBit has remained a significant share-holder in the ransomware ecosystem even during periods when newer groups such as Qilin or The Gentlemen surpassed it in public victim claims.

LockBit’s tradecraft is consistent with mature RaaS operations. Public reporting has linked the broader operation or its affiliates to exploitation of exposed remote access services, abuse of valid accounts, lateral movement over enterprise administration channels, and use of legitimate tools for reconnaissance, remote access, and data exfiltration. Observed behaviors associated with LockBit activity include use of Remote Desktop Protocol in intrusions and use of legitimate file-transfer software to support exfiltration. The group is also associated with rapid operational tempo once access is established, pressure-driven negotiations, and public leak-site shaming intended to coerce payment.

LockBit has been repeatedly connected to the wider Russian-speaking cybercrime ecosystem. It is not generally described as a state-directed espionage actor; rather, it is a financially motivated criminal enterprise. At the ecosystem level, infrastructure and service providers linked to LockBit have included bulletproof hosting operators and other criminal enablers that also serviced major ransomware and malware groups. Law-enforcement actions, sanctions, and infrastructure seizures have targeted both LockBit itself and parts of this enabling network, but the operation has shown resilience through affiliate mobility, reconstitution, and continued branding evolution.

LockBit remains a high-profile ransomware threat because of its scale, affiliate model, broad targeting, and ability to persist despite sustained international disruption efforts.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 20, 2026
Last activity
Jul 21, 2026
Feed role
C2 / Distribution
Host form
10 IP / 6 hostnames

Leading locations

  • NL4
  • CN3
  • US3
  • CA1
  • CH1
  • DE1
  • HK1
  • IE1
  • KR1

Leading providers

  • Amazon.com, Inc.3
  • Omegatech LTD3
  • China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch1
  • Cloudflare, Inc.1
  • CTG Server Limited1
  • DEDIK SERVICES LIMITED1

Infrastructure traits

  • Hosting 15
  • Anycast 1
  • Proxy 1

Samples

Recent associated samples

MITRE ATT&CK

LockBit in ATT&CK

114 distinct techniques

Techniques

114 techniques
T1203 Exploitation for Client Execution T1486 Data Encrypted for Impact T1048 Exfiltration Over Alternative Protocol T1021.001 Remote Desktop Protocol T1566 Phishing T1498 Network Denial of Service T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1568.001 Fast Flux DNS T1583.001 Domains T1110 Brute Force T1583.006 Web Services T1555 Credentials from Password Stores T1021 Remote Services T1570 Lateral Tool Transfer T1567 Exfiltration Over Web Service T1190 Exploit Public-Facing Application T1078 Valid Accounts T1657 Financial Theft T1562.002 Disable Windows Event Logging T1562.001 Disable or Modify Tools T1574.001 DLL T1562 Impair Defenses T1027 Obfuscated Files or Information T1620 Reflective Code Loading T1027.007 Dynamic API Resolution T1070.004 File Deletion T1140 Deobfuscate/Decode Files or Information T1070 Indicator Removal T1497 Virtualization/Sandbox Evasion T1560.001 Archive via Utility T1027.002 Software Packing T1133 External Remote Services T1497.001 System Checks T1622 Debugger Evasion T1548.002 Bypass User Account Control T1090 Proxy T1489 Service Stop T1491.001 Internal Defacement T1059 Command and Scripting Interpreter T1567.002 Exfiltration to Cloud Storage T1572 Protocol Tunneling T1543.003 Windows Service T1021.002 SMB/Windows Admin Shares T1219 Remote Access Tools T1189 Drive-by Compromise T1041 Exfiltration Over C2 Channel T1110.003 Password Spraying T1078.001 Default Accounts T1078.002 Domain Accounts T1047 Windows Management Instrumentation T1003.001 LSASS Memory T1574 Hijack Execution Flow T1059.001 PowerShell T1218.003 CMSTP T1490 Inhibit System Recovery T1529 System Shutdown/Reboot T1027.005 Indicator Removal from Tools T1070.001 Clear Windows Event Logs T1055 Process Injection T1119 Automated Collection T1485 Data Destruction T1068 Exploitation for Privilege Escalation T1003 OS Credential Dumping T1082 System Information Discovery T1482 Domain Trust Discovery T1071.001 Web Protocols T1059.003 Windows Command Shell T1558 Steal or Forge Kerberos Tickets T1547.001 Registry Run Keys / Startup Folder T1569.002 Service Execution T1136 Create Account T1021.004 SSH T1074 Data Staged T1016 System Network Configuration Discovery T1537 Transfer Data to Cloud Account T1583 Acquire Infrastructure T1505.003 Web Shell T1090.003 Multi-hop Proxy T1213 Data from Information Repositories T1020 Automated Exfiltration T1204 User Execution T1210 Exploitation of Remote Services T1573 Encrypted Channel T1614 System Location Discovery T1083 File and Directory Discovery T1561 Disk Wipe T1614.001 System Language Discovery T1055.012 Process Hollowing T1059.004 Unix Shell T1195 Supply Chain Compromise T1135 Network Share Discovery T1548 Abuse Elevation Control Mechanism T1014 Rootkit T1018 Remote System Discovery T1654 Log Enumeration T1556 Modify Authentication Process T1484.001 Group Policy Modification T1056.001 Keylogging T1036 Masquerading T1106 Native API T1562.004 Disable or Modify System Firewall T1057 Process Discovery T1112 Modify Registry T1562.009 Safe Mode Boot T1134.001 Token Impersonation/Theft T1120 Peripheral Device Discovery T1546.015 Component Object Model Hijacking T1559.001 Component Object Model T1007 System Service Discovery T1046 Network Service Discovery T1547 Boot or Logon Autostart Execution T1561.001 Disk Content Wipe T1056 Input Capture

Reporting

Research mentioning LockBit

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.