Skip to content

LockBit

LockBit is a prolific Russian-speaking ransomware-as-a-service operation that emerged in the early 2020s and became one of the most active and widely recognized cybercriminal extortion groups of the decade.

Profile source: Mallory opens in a new tab

LockBit

Family profile

LockBit is a prolific Russian-speaking ransomware-as-a-service operation that emerged in the early 2020s and became one of the most active and widely recognized cybercriminal extortion groups of the decade. It operates through a core team that develops and maintains ransomware tooling and leak-site infrastructure while relying on affiliates to obtain access to victim networks, conduct intrusions, exfiltrate data, and deploy encryption at scale. Common aliases and branding variants include LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, and more recent references to LockBit 5.0; reporting also frequently refers to LockBit affiliates as a distinct operational layer within the broader ecosystem.

LockBit has targeted organizations globally across government, healthcare, manufacturing, finance, education, telecommunications, logistics, and other sectors, generally in opportunistic campaigns rather than a single narrow vertical. The group is known for double-extortion operations in which data is stolen before encryption and victims are threatened with public exposure if they do not pay. Law-enforcement reporting has shown that victim data was retained on LockBit-controlled infrastructure even after some ransom payments, reinforcing long-standing concerns that payment does not reliably result in deletion of stolen information.

Operationally, LockBit and its affiliates have used a broad range of initial access vectors typical of mature human-operated ransomware programs, including exploitation of edge-device and remote-access vulnerabilities, abuse of exposed RDP and VPN services, credential-based compromise, and purchased access from criminal intermediaries. Public reporting has specifically linked LockBit affiliates to exploitation of high-profile vulnerabilities such as CVE-2023-4966. Post-compromise behavior commonly includes lateral movement, privilege escalation, credential theft, defense evasion, data exfiltration, and enterprise-wide ransomware deployment. LockBit-linked activity has also been associated with the use of legitimate administrative and remote-access tooling, as well as common exfiltration utilities, reflecting a pragmatic tradecraft model centered on speed and scale.

The group’s ecosystem has been resilient despite major disruption efforts. A 2024 law-enforcement takedown targeted LockBit infrastructure, but the broader affiliate model and surrounding criminal service providers enabled continued activity and reconstitution. LockBit has also depended on external enabling infrastructure, including bulletproof hosting providers that have been accused by governments of supporting LockBit operations alongside other ransomware groups. Sanctions and criminal actions against such providers have highlighted LockBit’s integration into a wider Russian cybercrime support environment.

LockBit has been repeatedly cited as one of the most prolific ransomware groups of the early 2020s and has remained relevant in later reporting even as newer groups gained market share. Variants and affiliate clusters under the LockBit name have continued to appear in victim-leak reporting, and former LockBit affiliates have reportedly migrated to or collaborated with other ransomware programs. Overall, LockBit is best understood as a durable, affiliate-driven extortion enterprise rooted in the Russian-speaking cybercriminal ecosystem, notable for high operational tempo, broad victimology, repeated rebranding, and sustained impact despite international law-enforcement pressure.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 1, 2026
Last activity
Aug 7, 2026
Feed role
C2 / Distribution
Host form
27 IP / 11 hostnames

Leading locations

  • CN8
  • US8
  • DE5
  • NL4
  • KZ2
  • LU2
  • RU2
  • BG1
  • CA1
  • ES1
  • FR1
  • HK1

Leading providers

  • Amazon.com, Inc.3
  • Shenzhen Tencent Computer Systems Company Limited3
  • CHINA UNICOM China169 Backbone2
  • Ghosty Networks LLC2
  • Hetzner Online GmbH2
  • JSC Transtelecom2

Infrastructure traits

  • Hosting 28
  • Anycast 1
  • Vpn 1

Samples

Recent associated samples

MITRE ATT&CK

LockBit in ATT&CK

118 distinct techniques

Techniques

118 techniques
T1486 Data Encrypted for Impact T1568 Dynamic Resolution T1580 Cloud Infrastructure Discovery T1195 Supply Chain Compromise T1090.003 Multi-hop Proxy T1583.003 Virtual Private Server T1583.004 Server T1665 Hide Infrastructure T1583.006 Web Services T1190 Exploit Public-Facing Application T1657 Financial Theft T1490 Inhibit System Recovery T1537 Transfer Data to Cloud Account T1048 Exfiltration Over Alternative Protocol T1074 Data Staged T1203 Exploitation for Client Execution T1021.001 Remote Desktop Protocol T1566 Phishing T1498 Network Denial of Service T1105 Ingress Tool Transfer T1071 Application Layer Protocol T1568.001 Fast Flux DNS T1583.001 Domains T1110 Brute Force T1555 Credentials from Password Stores T1021 Remote Services T1570 Lateral Tool Transfer T1567 Exfiltration Over Web Service T1078 Valid Accounts T1562.002 Disable Windows Event Logging T1562.001 Disable or Modify Tools T1574.001 DLL T1562 Impair Defenses T1027 Obfuscated Files or Information T1620 Reflective Code Loading T1027.007 Dynamic API Resolution T1070.004 File Deletion T1140 Deobfuscate/Decode Files or Information T1070 Indicator Removal T1497 Virtualization/Sandbox Evasion T1560.001 Archive via Utility T1027.002 Software Packing T1133 External Remote Services T1497.001 System Checks T1622 Debugger Evasion T1548.002 Bypass User Account Control T1090 Proxy T1489 Service Stop T1491.001 Internal Defacement T1059 Command and Scripting Interpreter T1567.002 Exfiltration to Cloud Storage T1572 Protocol Tunneling T1543.003 Windows Service T1021.002 SMB/Windows Admin Shares T1219 Remote Access Tools T1189 Drive-by Compromise T1041 Exfiltration Over C2 Channel T1110.003 Password Spraying T1078.001 Default Accounts T1078.002 Domain Accounts T1047 Windows Management Instrumentation T1003.001 LSASS Memory T1574 Hijack Execution Flow T1059.001 PowerShell T1218.003 CMSTP T1529 System Shutdown/Reboot T1027.005 Indicator Removal from Tools T1070.001 Clear Windows Event Logs T1055 Process Injection T1119 Automated Collection T1485 Data Destruction T1068 Exploitation for Privilege Escalation T1003 OS Credential Dumping T1082 System Information Discovery T1482 Domain Trust Discovery T1071.001 Web Protocols T1059.003 Windows Command Shell T1558 Steal or Forge Kerberos Tickets T1547.001 Registry Run Keys / Startup Folder T1569.002 Service Execution T1136 Create Account T1021.004 SSH T1016 System Network Configuration Discovery T1583 Acquire Infrastructure T1505.003 Web Shell T1213 Data from Information Repositories T1020 Automated Exfiltration T1204 User Execution T1210 Exploitation of Remote Services T1573 Encrypted Channel T1614 System Location Discovery T1083 File and Directory Discovery T1561 Disk Wipe T1614.001 System Language Discovery T1055.012 Process Hollowing T1059.004 Unix Shell T1135 Network Share Discovery T1548 Abuse Elevation Control Mechanism T1014 Rootkit T1018 Remote System Discovery T1654 Log Enumeration T1556 Modify Authentication Process T1484.001 Group Policy Modification T1056.001 Keylogging T1036 Masquerading T1106 Native API T1562.004 Disable or Modify System Firewall T1057 Process Discovery T1112 Modify Registry T1562.009 Safe Mode Boot T1134.001 Token Impersonation/Theft T1120 Peripheral Device Discovery T1546.015 Component Object Model Hijacking T1559.001 Component Object Model T1007 System Service Discovery T1046 Network Service Discovery T1547 Boot or Logon Autostart Execution T1561.001 Disk Content Wipe

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.