Last seven days
- First activity
- Aug 1, 2026
- Last activity
- Aug 7, 2026
- Feed role
- C2 / Distribution
- Host form
- 27 IP / 11 hostnames
LockBit is a prolific Russian-speaking ransomware-as-a-service operation that emerged in the early 2020s and became one of the most active and widely recognized cybercriminal extortion groups of the decade.
Profile source: Mallory opens in a new tabLockBit
LockBit is a prolific Russian-speaking ransomware-as-a-service operation that emerged in the early 2020s and became one of the most active and widely recognized cybercriminal extortion groups of the decade. It operates through a core team that develops and maintains ransomware tooling and leak-site infrastructure while relying on affiliates to obtain access to victim networks, conduct intrusions, exfiltrate data, and deploy encryption at scale. Common aliases and branding variants include LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, and more recent references to LockBit 5.0; reporting also frequently refers to LockBit affiliates as a distinct operational layer within the broader ecosystem.
LockBit has targeted organizations globally across government, healthcare, manufacturing, finance, education, telecommunications, logistics, and other sectors, generally in opportunistic campaigns rather than a single narrow vertical. The group is known for double-extortion operations in which data is stolen before encryption and victims are threatened with public exposure if they do not pay. Law-enforcement reporting has shown that victim data was retained on LockBit-controlled infrastructure even after some ransom payments, reinforcing long-standing concerns that payment does not reliably result in deletion of stolen information.
Operationally, LockBit and its affiliates have used a broad range of initial access vectors typical of mature human-operated ransomware programs, including exploitation of edge-device and remote-access vulnerabilities, abuse of exposed RDP and VPN services, credential-based compromise, and purchased access from criminal intermediaries. Public reporting has specifically linked LockBit affiliates to exploitation of high-profile vulnerabilities such as CVE-2023-4966. Post-compromise behavior commonly includes lateral movement, privilege escalation, credential theft, defense evasion, data exfiltration, and enterprise-wide ransomware deployment. LockBit-linked activity has also been associated with the use of legitimate administrative and remote-access tooling, as well as common exfiltration utilities, reflecting a pragmatic tradecraft model centered on speed and scale.
The groupβs ecosystem has been resilient despite major disruption efforts. A 2024 law-enforcement takedown targeted LockBit infrastructure, but the broader affiliate model and surrounding criminal service providers enabled continued activity and reconstitution. LockBit has also depended on external enabling infrastructure, including bulletproof hosting providers that have been accused by governments of supporting LockBit operations alongside other ransomware groups. Sanctions and criminal actions against such providers have highlighted LockBitβs integration into a wider Russian cybercrime support environment.
LockBit has been repeatedly cited as one of the most prolific ransomware groups of the early 2020s and has remained relevant in later reporting even as newer groups gained market share. Variants and affiliate clusters under the LockBit name have continued to appear in victim-leak reporting, and former LockBit affiliates have reportedly migrated to or collaborated with other ransomware programs. Overall, LockBit is best understood as a durable, affiliate-driven extortion enterprise rooted in the Russian-speaking cybercriminal ecosystem, notable for high operational tempo, broad victimology, repeated rebranding, and sustained impact despite international law-enforcement pressure.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 c322fa3e02a79ecead674bc4a8e67b71d14632427f8dc9a380b0f588941bbf1a f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f5ebd8f8e5217df1c726beb523c00d49992d6d205589509cbe2c581b6aab29b6 16930620b3b9166e0ffbd98f5d5b580c9919fd6ccdcc74fb996f53577f508267 4e5cebe1908e12e8a4ed1198fb01fb87871dbe54847855b11b3540dbc47bbe88 6ff59d49647c897e8c134519f5eb73ff53bd55386a24c55058e7427598d5a754 ecda70414eaa3354ef877c71c445d49294f142fc694e81f0002d385ff1060d02 0f78a658b60f0879acccf0933d9ae8a5d2c188e9f16b8e6f7b01bd0cc9b5c4e1 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.