Skip to content

LockBit

LockBit is a ransomware-as-a-service operation that emerged in September 2019 as ABCD, rebranding as LockBit 2.0 in 2021 and LockBit 3.0, also known as LockBit Black, in 2022.

Profile source: Mallory opens in a new tab

LockBit

Family profile

LockBit is a ransomware-as-a-service operation that emerged in September 2019 as ABCD, rebranding as LockBit 2.0 in 2021 and LockBit 3.0, also known as LockBit Black, in 2022. The operation supplies affiliates with encryption tooling, decryption capabilities, payment infrastructure, and technical support in exchange for a share of ransom proceeds. LockBit has targeted organizations worldwide, notably in healthcare, financial services, manufacturing, education, government, and critical-service sectors, with substantial victimization reported in the United States, United Kingdom, Germany, France, and Australia.

LockBit affiliates commonly obtain access through exposed or vulnerable VPN and Remote Desktop services, exploitation of public-facing applications, and password spraying or brute-force activity. Observed intrusions include credential dumping, Active Directory and network reconnaissance, privilege escalation, lateral movement through remote administration mechanisms, deployment of legitimate remote-access tools for persistence, and defense evasion through security-control modification. Affiliates have also used publicly disclosed vulnerabilities in PaperCut products for initial access and subsequent LockBit deployment.

LockBit ransomware operations commonly employ double extortion: operators exfiltrate victim data before encrypting systems and threaten public disclosure if payment is not made. Some affiliate activity has involved triple-extortion tactics, including threats of distributed denial-of-service attacks or direct pressure on victims' customers and partners. LockBit 2.0 also solicited insiders through ransom-note and desktop-wallpaper messaging, seeking corporate VPN, remote desktop, and email access. LockBit has supported ransomware payloads targeting Windows, Linux, and ESXi environments.

Capabilities

  • Brute Force
  • Credential Theft
  • Ddos
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Initial Access
  • Lateral Movement
  • Persistence
  • Privilege Escalation
  • Reconnaissance

Operational record

1
YARA rules
5
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

47 named in public reporting
LockBit

Uit onderzoek bleek dat de LockBit 3.0 groep achter de hack zit. Alle servers, back-ups en data waren versleuteld met ransomware.

TA505

In 2023, a critical flaw in PaperCut MF and NG (CVE-2023-27350, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.

Storm2603

Warlock appears to be a customized derivative of the leaked LockBit 3.0 builder. In mid-2025, threat actor Storm2603 deployed both LockBit Black and Warlock in the same attack chains against SharePoint environments.

Water Manaul

Warlock previously deployed LockBit-derived ransomware with the .x2anylock extension.

Head Mare

Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky.

THREEAM (3AM)

例えば「 LockBit 」は 7 月、 8 月とリークサイト掲載数にして全体の 30 %以上を占めていましたが、今月は 14.4% とその割合を落としています。

Wazawaka

Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.

Bassterlord

A member of the cybercriminal community has discovered and disclosed a bug in the LockBit ransomware that could have been used for free decryptions. The bug impacts LockBit, a ransomware-as-a-service (RaaS) operation...

UNC24655

SMOKEDHAM ... a été utilisée par UNC24655, un affilié RaaS précédemment associé aux groupes Lockbit et Darkside.

Conti

Upon investigation and analysis, we have determined that the new LockBit 3.0 variant has a high infection vector and attack chain exhibiting substantial anti-forensic activity.

GOLD MYSTIC

However, other threat groups have used TrickBot to distribute ransomware such as RansomExx (also known as 777), Maze, and LockBit.

Twisted Spider

Этот крипто-вымогатель шифрует данные компаний и бизнес-пользователей с помощью AES + RSA... Позже, в конце декабря 2019, в коде и названии появилось слово LockBit... Еще позже появились более новые версии: 3.0, 4.0, 5.0.

INDRIK SPIDER

Referred to as Gold Drake and Indrik Spider, the financially motivated hacking group has historically operated the Dridex malware and has since switched to deploying a string of ransomware families over the years, including most recently LockBit.

BlooDy

A postmortem analysis of multiple incidents in which attackers eventually launched the latest version of LockBit ransomware (known variously as LockBit 3.0 or ‘LockBit Black’)

Syrphid

Symantec, a division of Broadcom Software, has observed threat actors targeting server machines in order to spread the LockBit ransomware threat throughout compromised networks.

ShadowSyndicate

We found connections between ShadowSyndicate infrastructure and Citrix Bleed attack infrastructure that spread Lockbit ransomware.

Toy Ghouls

Ce groupe utilisait auparavant des ransomwares tiers (RedAlert, LockBit, Babuk).

UAT-8099

In a real-world case, evidence was found that the threat actor, believed to be UAT-8099, used LockBit 3.0 Ransomware; after uploading a web shell, they attempted to gain control and manipulate SEO using Potato, AnyDesk, GotoHTTP, LCX, the NPS client (npc.Exe), BadIIS...

WIZARD SPIDER

We investigated a recent LockBit extortion incident that occurred in Q3 2023... In September 2019, Cybereason found this hostname in old LockBit 2.0 extortions...

DragonForce

CYBLE identified the DragonForce ransomware binary as being based on LockBit 3.0 (Black) ransomware.

Twelve

The attackers used a version of the popular LockBit 3.0 ransomware, compiled from publicly available source code, to encrypt the data.

CyberVolk

The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.

Storm-2603

Talos IR responded to Warlock, Babuk, and Kraken ransomware variants for the first time, while also responding to previously seen families Qilin and LockBit.

Nullbulge

NullBulge is delivering LockBit ransomware payloads to their Async and Xworm victims as a later-stage infection.

Cinnamon Tempest

During a recent investigation, our DFIR team discovered that LockBit Ransomware-as-a-Service (Raas) side-loads Cobalt Strike Beacon through a signed VMware xfer logs command line utility.

Crypt Ghouls

As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.

MorLock

As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.

Silent Ransom Group

UNC3753 traces back to the now-defunct Conti ransomware gang, sharing overlaps with UNC2686, which ran BazarCall-style campaigns from 2021. The group deployed LockBit Black in 2022 but dropped ransomware entirely after that, focusing purely on data theft and extortion.

PhantomCore

Impact T1486 Data Encrypted for Impact PhantomCore использовали LockBit 3.0 для шифрования трафика

DEV-0216

Around November 2021, DEV-0243 started to deploy the LockBit 2.0 RaaS payload in their intrusions. ... In a notable shift ... DEV-0401 started deploying LockBit 2.0 ransomware payloads in April 2022.

CosmicBeetle

CosmicBeetle, an immature ransomware threat actor using its own signature encryptor, ScRansom, and the leaked LockBit 3.0 builder, became an affiliate of RansomHub.

UAC-0238

Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

Hastalamuerte

LockBit posted 163 victims in Q1 2026, climbing to fourth place globally.

Warlock

...or generated using the leaked LockBit Black builder.

Mustard Tempest

"In 2024, a member of Evil Corp was identified as an affiliate of the LockBit ransomware-as-a-service (RaaS) scheme."

BlackJack

The attackers used a version of the popular LockBit 3.0 ransomware, compiled from publicly available source code, to encrypt the data.

Storm-0501

...delivering various ransomware payloads over the years, including ... LockBit ... ransomware...; ...DragonForce... using a variant of the leaked LockBit3.0 builder...

Storm-1175

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

Storm-0506

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

Scattered Spider

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

UNC2465

UNC2465, which used the Darkside and Lockbit ransomware...

Bl00Dy

Bl00Dy ... used open-source and leaked builders from other operators, including LockBit, Babuk and Conti. From September 2022, the group used the LockBit ransomware builder in its attacks... Similarly, the DragonForce ransomware binary was also revealed to have been likely generated using the LockBit Black builder.

Bearlyfy

...Bearlyfy that has used ransomware strains like LockBit 3.0 and Babuk...

FIN7

The LockBit gang began its operation in September 2019 and was first known as “ABCD ransomware.” ... Over the next six months, LockBit worked on a new project, internally referred to as “LockBit Red,” and publicly known as “LockBit 2.0.” ... LockBit officially announced another major release ... LockBit Black (publicly known as LockBit 3.0).

ExCobalt

Lockers such as Babuk and LockBit.

Mora_001

The ransomware strain observed in these incidents closely resembles LockBit 3.0 (LockBit Black).

Exploited software

Vulnerabilities linked to LockBit

31 CVEs
CVE-2023-27350 PaperCut MF/NG SetupCompleted Authentication Bypass RCE CVE-2023-27351 PaperCut NG/MF Authentication Bypass CVE-2025-53770 ToolShell: Unauthenticated RCE in On-Premises Microsoft SharePoint Server CVE-2023-27532 Unauthenticated Credential Extraction in Veeam Backup & Replication CVE-2023-4966 Citrix Bleed CVE-2019-11510 Pulse Connect Secure Unauthenticated Arbitrary File Read CVE-2018-13379 FortiOS and FortiProxy SSL VPN Pre-Authentication Path Traversal CVE-2023-46604 Apache ActiveMQ OpenWire Deserialization Remote Code Execution CVE-2021-44228 Log4Shell CVE-2024-55591 FortiOS and FortiProxy Node.js WebSocket Authentication Bypass CVE-2023-3519 Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2019-7481 SQL Injection in SonicWall SMA100 CVE-2021-20028 SQL Injection in SonicWall Secure Remote Access (SRA) Appliances CVE-2025-6264 Privilege Escalation in Rapid7 Velociraptor Admin.Client.UpdateClientConfig Artifact CVE-2025-53771 Microsoft SharePoint Server Path Traversal Spoofing CVE-2025-24472 Fortinet FortiOS and FortiProxy CSF Proxy Authentication Bypass CVE-2022-41082 ProxyNotShell RCE in Microsoft Exchange Server CVE-2022-41040 ProxyNotShell SSRF in Microsoft Exchange Server CVE-2022-21969 RCE in Microsoft Exchange Server (CVE-2022-21969) CVE-2023-3824 Stack Buffer Overflow in PHP PHAR Directory Entry Parsing CVE-2026-1731 Pre-authentication OS Command Injection in BeyondTrust Remote Support and Privileged Remote Access CVE-2025-49704 Microsoft SharePoint Code Injection Vulnerability CVE-2025-49706 Microsoft SharePoint Improper Authentication Spoofing Vulnerability CVE-2024-37085 Authentication Bypass in VMware ESXi Active Directory Integration CVE-2024-1708 Path Traversal in ConnectWise ScreenConnect CVE-2020-1472 Zerologon CVE-2024-1709 ConnectWise ScreenConnect Authentication Bypass CVE-2026-27446 Missing authentication in Apache Artemis Core downstream federation CVE-2023-0669 Fortra GoAnywhere Managed File Transfer - HIGH - CVSS 7.2 CVE-2021-22986 F5 iControl REST - CRITICAL - CVSS 9.8 CVE-2019-0708 Windows Remote Desktop Services - CRITICAL - CVSS 9.8

MITRE ATT&CK

LockBit in ATT&CK

119 distinct techniques

Techniques

119 techniques
T1486 Data Encrypted for Impact T1046 Network Service Discovery T1021 Remote Services T1657 Financial Theft T1190 Exploit Public-Facing Application T1567 Exfiltration Over Web Service T1620 Reflective Code Loading T1059.001 PowerShell T1027 Obfuscated Files or Information T1562 Impair Defenses T1059 Command and Scripting Interpreter T1106 Native API T1021.001 Remote Desktop Protocol T1497.001 System Checks T1070.004 File Deletion T1189 Drive-by Compromise T1078 Valid Accounts T1203 Exploitation for Client Execution T1105 Ingress Tool Transfer T1070.001 Clear Windows Event Logs T1566.001 Spearphishing Attachment T1567.002 Exfiltration to Cloud Storage T1566 Phishing T1213 Data from Information Repositories T1041 Exfiltration Over C2 Channel T1489 Service Stop T1021.002 SMB/Windows Admin Shares T1018 Remote System Discovery T1047 Windows Management Instrumentation T1529 System Shutdown/Reboot T1497 Virtualization/Sandbox Evasion T1491 Defacement T1070 Indicator Removal T1565 Data Manipulation T1057 Process Discovery T1222 File and Directory Permissions Modification T1548.002 Bypass User Account Control T1218.005 Mshta T1053 Scheduled Task/Job T1036 Masquerading T1543 Create or Modify System Process T1534 Internal Spearphishing T1135 Network Share Discovery T1548 Abuse Elevation Control Mechanism T1614.001 System Language Discovery T1120 Peripheral Device Discovery T1218 System Binary Proxy Execution T1112 Modify Registry T1622 Debugger Evasion T1547.001 Registry Run Keys / Startup Folder T1484.001 Group Policy Modification T1059.004 Unix Shell T1559.001 Component Object Model T1564.003 Hidden Window T1134.001 Token Impersonation/Theft T1570 Lateral Tool Transfer T1562.001 Disable or Modify Tools T1553 Subvert Trust Controls T1053.005 Scheduled Task T1102 Web Service T1490 Inhibit System Recovery T1133 External Remote Services T1573 Encrypted Channel T1055 Process Injection T1082 System Information Discovery T1564 Hide Artifacts T1059.003 Windows Command Shell T1491.001 Internal Defacement T1484 Domain or Tenant Policy Modification T1049 System Network Connections Discovery T1537 Transfer Data to Cloud Account T1218.002 Control Panel T1005 Data from Local System T1560 Archive Collected Data T1110 Brute Force T1569.002 Service Execution T1586.002 Email Accounts T1027.009 Embedded Payloads T1068 Exploitation for Privilege Escalation T1480.002 Mutual Exclusion T1003 OS Credential Dumping T1204.002 Malicious File T1027.011 Fileless Storage T1090 Proxy T1547.009 Shortcut Modification T1071 Application Layer Protocol T1056.001 Keylogging T1543.003 Windows Service T1553.005 Mark-of-the-Web Bypass T1016 System Network Configuration Discovery T1562.009 Safe Mode Boot T1485 Data Destruction T1210 Exploitation of Remote Services T1546.008 Accessibility Features T1547.004 Winlogon Helper DLL T1083 File and Directory Discovery T1059.006 Python T1059.005 Visual Basic T1021.005 VNC T1583 Acquire Infrastructure T1027.002 Software Packing T1588.001 Malware T1218.001 Compiled HTML File T1074 Data Staged T1134 Access Token Manipulation T1007 System Service Discovery T1071.001 Web Protocols T1048 Exfiltration Over Alternative Protocol T1574 Hijack Execution Flow T1586 Compromise Accounts T1195 Supply Chain Compromise T1219 Remote Access Tools T1218.007 Msiexec T1027.007 Dynamic API Resolution T1560.001 Archive via Utility T1572 Protocol Tunneling T1003.001 OS Credential Dumping: LSASS Memory T1482 Domain Trust Discovery T1090.003 Proxy: Multi-hop Proxy

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.