Last seven days
- First activity
- Jul 20, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2 / Distribution
- Host form
- 10 IP / 6 hostnames
LockBit is a prolific cybercriminal ransomware-as-a-service operation that has been one of the most active and recognizable extortion threats globally since its emergence in 2019.
Profile source: Mallory opens in a new tabLockBit
LockBit is a prolific cybercriminal ransomware-as-a-service operation that has been one of the most active and recognizable extortion threats globally since its emergence in 2019. It operates through a core development and management team supported by affiliates who conduct intrusions, steal data, deploy ransomware, and negotiate extortion demands. The group is widely associated with double-extortion operations that combine file encryption with threats to publish stolen information, and it has repeatedly demonstrated the ability to rebrand, rebuild infrastructure, and continue operations after disruption.
LockBit is commonly referenced through multiple versioned and branding variants, including LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, and more recent references to LockBit 5.0. “LockBit Black” is broadly associated with the LockBit 3.0 generation. Reporting also frequently distinguishes the core operation from its affiliates, reflecting the group’s franchise-like operating model.
The operation has targeted organizations across a wide range of sectors and geographies, including manufacturing, government, healthcare, technology, retail, consulting, education, and critical services. Victimology has historically been heavily weighted toward the United States, but more recent reporting indicates broader international distribution, with sustained activity across Europe, Latin America, and Asia. LockBit has remained a significant share-holder in the ransomware ecosystem even during periods when newer groups such as Qilin or The Gentlemen surpassed it in public victim claims.
LockBit’s tradecraft is consistent with mature RaaS operations. Public reporting has linked the broader operation or its affiliates to exploitation of exposed remote access services, abuse of valid accounts, lateral movement over enterprise administration channels, and use of legitimate tools for reconnaissance, remote access, and data exfiltration. Observed behaviors associated with LockBit activity include use of Remote Desktop Protocol in intrusions and use of legitimate file-transfer software to support exfiltration. The group is also associated with rapid operational tempo once access is established, pressure-driven negotiations, and public leak-site shaming intended to coerce payment.
LockBit has been repeatedly connected to the wider Russian-speaking cybercrime ecosystem. It is not generally described as a state-directed espionage actor; rather, it is a financially motivated criminal enterprise. At the ecosystem level, infrastructure and service providers linked to LockBit have included bulletproof hosting operators and other criminal enablers that also serviced major ransomware and malware groups. Law-enforcement actions, sanctions, and infrastructure seizures have targeted both LockBit itself and parts of this enabling network, but the operation has shown resilience through affiliate mobility, reconstitution, and continued branding evolution.
LockBit remains a high-profile ransomware threat because of its scale, affiliate model, broad targeting, and ability to persist despite sustained international disruption efforts.
C2 tracking
Derp observations, rolling seven-day window
Samples
27dc2e511f4da03bc10b975156996133c8654defc24d40b829ff7d955be4e2ce 2e74827318235a497133219963a2205cd8d7779a195ec67d740d825599210932 5594d4a2153e25d5de0de21bc958e1d11a341679ea2fec2123567fa3547c7847 7ef34bf0c59089432586e8847b5a8d7439a28ed3aca3254fab49ef13723be65e c4617e465670873ca7de2d8898e8c349d8189b86561fc5b8996c4d8bab251801 2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 27c2134b7774f29e657f881ca9177fe6e93a9b6e03fda4579168b9099c0005a8 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 5bcc428f37655c7bc16110cc2127c510f66827a382cb1c9fa251b15a7d2c214b MITRE ATT&CK
Reporting
...un service d’hébergement dit « bullet-proof » ... Dont certains groupes très actifs, comme LockBit, l’ancien numéro un du rançongiciel...
GuidePoint observed a noticeable shift in targeting patterns, with the U.S. accounting for a smaller proportion of victims than in previous quarters... linked this broader geographic distribution to increased activity from groups including Qilin, The Gentlemen and LockBit.
This operating model resembles that of groups such as LockBit and BlackCat (ALPHV), where the core team is responsible not only for ransomware development but also for defining how operations are conducted.
LockBit 5.0 (7 revendications chacun) complètent le tableau.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.