Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 4, 2026
- Feed role
- C2 / Distribution
- Host form
- 53 IP / 26 hostnames
LockBit is a prolific Russian-speaking ransomware-as-a-service operation that emerged in the early 2020s and became one of the most active and widely recognized cybercriminal extortion groups of the decade.
Profile source: Mallory opens in a new tabLockBit
LockBit is a prolific Russian-speaking ransomware-as-a-service operation that emerged in the early 2020s and became one of the most active and widely recognized cybercriminal extortion groups of the decade. It operates through a core team that develops and maintains ransomware tooling and leak-site infrastructure while relying on affiliates to obtain access to victim networks, conduct intrusions, exfiltrate data, and deploy encryption at scale. Common aliases and branding variants include LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, and more recent references to LockBit 5.0; reporting also frequently refers to LockBit affiliates as a distinct operational layer within the broader ecosystem.
LockBit has targeted organizations globally across government, healthcare, manufacturing, finance, education, telecommunications, logistics, and other sectors, generally in opportunistic campaigns rather than a single narrow vertical. The group is known for double-extortion operations in which data is stolen before encryption and victims are threatened with public exposure if they do not pay. Law-enforcement reporting has shown that victim data was retained on LockBit-controlled infrastructure even after some ransom payments, reinforcing long-standing concerns that payment does not reliably result in deletion of stolen information.
Operationally, LockBit and its affiliates have used a broad range of initial access vectors typical of mature human-operated ransomware programs, including exploitation of edge-device and remote-access vulnerabilities, abuse of exposed RDP and VPN services, credential-based compromise, and purchased access from criminal intermediaries. Public reporting has specifically linked LockBit affiliates to exploitation of high-profile vulnerabilities such as CVE-2023-4966. Post-compromise behavior commonly includes lateral movement, privilege escalation, credential theft, defense evasion, data exfiltration, and enterprise-wide ransomware deployment. LockBit-linked activity has also been associated with the use of legitimate administrative and remote-access tooling, as well as common exfiltration utilities, reflecting a pragmatic tradecraft model centered on speed and scale.
The groupβs ecosystem has been resilient despite major disruption efforts. A 2024 law-enforcement takedown targeted LockBit infrastructure, but the broader affiliate model and surrounding criminal service providers enabled continued activity and reconstitution. LockBit has also depended on external enabling infrastructure, including bulletproof hosting providers that have been accused by governments of supporting LockBit operations alongside other ransomware groups. Sanctions and criminal actions against such providers have highlighted LockBitβs integration into a wider Russian cybercrime support environment.
LockBit has been repeatedly cited as one of the most prolific ransomware groups of the early 2020s and has remained relevant in later reporting even as newer groups gained market share. Variants and affiliate clusters under the LockBit name have continued to appear in victim-leak reporting, and former LockBit affiliates have reportedly migrated to or collaborated with other ransomware programs. Overall, LockBit is best understood as a durable, affiliate-driven extortion enterprise rooted in the Russian-speaking cybercriminal ecosystem, notable for high operational tempo, broad victimology, repeated rebranding, and sustained impact despite international law-enforcement pressure.
C2 tracking
Derp observations, rolling seven-day window
Samples
2fcad226b17131da4274e1b9f8f31359bdd325c9568665f08fd1f6c5d06a23ce 30daba44a4a25ff5750508613f897057a55337458f19b562e2ed1172c77e626b 7126b9932dc0cdfe751340edfa7c4a14b69262eb1afd0530e6d1fdb2e25986dd 73ddf0df4e9e3866511ef9eae421b11615b81491d0db1d4a7ed19441e368ecef b914abc696286a639a847d2e3a4a36ff682f30a87b08c4ffc61f2e0cf5e7ec5f 1b723594e574c00aac2c946ff738a0454f7c24f6ebc84ae45a6af9628b08cb96 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 4e5cc8cb98584335400d00f0a0803c3e0202761f3fbe50bcab3858a80df255e1 65ba3988d38f83b9ee1f31cafa5bd37dc6b72279f5618aac94d71a904efa0cac d780677e97da00b2b90849741720c1a02e758356630b63242a18074775c69e1c MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.