Credential Theft
- Gosecretsdump
- LaZagne
- LostMyPassword
- Mimikatz
- NirSoft ExtPassword
- PasswordFox
- ProcDump
- Veeam-Get-Creds
LockBit is a ransomware-as-a-service operation that emerged in September 2019 as ABCD, rebranding as LockBit 2.0 in 2021 and LockBit 3.0, also known as LockBit Black, in 2022.
Profile source: Mallory opens in a new tabLockBit
LockBit is a ransomware-as-a-service operation that emerged in September 2019 as ABCD, rebranding as LockBit 2.0 in 2021 and LockBit 3.0, also known as LockBit Black, in 2022. The operation supplies affiliates with encryption tooling, decryption capabilities, payment infrastructure, and technical support in exchange for a share of ransom proceeds. LockBit has targeted organizations worldwide, notably in healthcare, financial services, manufacturing, education, government, and critical-service sectors, with substantial victimization reported in the United States, United Kingdom, Germany, France, and Australia.
LockBit affiliates commonly obtain access through exposed or vulnerable VPN and Remote Desktop services, exploitation of public-facing applications, and password spraying or brute-force activity. Observed intrusions include credential dumping, Active Directory and network reconnaissance, privilege escalation, lateral movement through remote administration mechanisms, deployment of legitimate remote-access tools for persistence, and defense evasion through security-control modification. Affiliates have also used publicly disclosed vulnerabilities in PaperCut products for initial access and subsequent LockBit deployment.
LockBit ransomware operations commonly employ double extortion: operators exfiltrate victim data before encrypting systems and threaten public disclosure if payment is not made. Some affiliate activity has involved triple-extortion tactics, including threats of distributed denial-of-service attacks or direct pressure on victims' customers and partners. LockBit 2.0 also solicited insiders through ransom-note and desktop-wallpaper messaging, seeking corporate VPN, remote desktop, and email access. LockBit has supported ransomware payloads targeting Windows, Linux, and ESXi environments.
f954f24e6eb85ef1b64e315491dad816f828044c91ac00afffcd77b4ce6808578ff61e4156c10b085e0c2233f24e85011319da1523ec2a67bda016c15334c195b86aacec897b8376c23647c4f0e78fba15796971d60f9d71ad162060f0f76a02ba56b0c4a215b40cbe64f8f8b1f166ad7e525ef64a4e27fbb325d7cb4653f0a1d96d2bcf13d55740f3bb64d45d2db94d2b84852065e28974e4081826ff09ddc1150.171.30.1020.101.57.984.201.211.4023.54.127.20964.233.181.94199.232.210.172184.28.89.16720.12.23.50184.30.21.17140.69.42.241Reported operators
Uit onderzoek bleek dat de LockBit 3.0 groep achter de hack zit. Alle servers, back-ups en data waren versleuteld met ransomware.
In 2023, a critical flaw in PaperCut MF and NG (CVE-2023-27350, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
Warlock appears to be a customized derivative of the leaked LockBit 3.0 builder. In mid-2025, threat actor Storm2603 deployed both LockBit Black and Warlock in the same attack chains against SharePoint environments.
Warlock previously deployed LockBit-derived ransomware with the .x2anylock extension.
Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky.
例えば「 LockBit 」は 7 月、 8 月とリークサイト掲載数にして全体の 30 %以上を占めていましたが、今月は 14.4% とその割合を落としています。
Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.
A member of the cybercriminal community has discovered and disclosed a bug in the LockBit ransomware that could have been used for free decryptions. The bug impacts LockBit, a ransomware-as-a-service (RaaS) operation...
SMOKEDHAM ... a été utilisée par UNC24655, un affilié RaaS précédemment associé aux groupes Lockbit et Darkside.
Upon investigation and analysis, we have determined that the new LockBit 3.0 variant has a high infection vector and attack chain exhibiting substantial anti-forensic activity.
However, other threat groups have used TrickBot to distribute ransomware such as RansomExx (also known as 777), Maze, and LockBit.
Bassterlord was the newest affiliate to join the LockBit ransomware operation.
Этот крипто-вымогатель шифрует данные компаний и бизнес-пользователей с помощью AES + RSA... Позже, в конце декабря 2019, в коде и названии появилось слово LockBit... Еще позже появились более новые версии: 3.0, 4.0, 5.0.
Referred to as Gold Drake and Indrik Spider, the financially motivated hacking group has historically operated the Dridex malware and has since switched to deploying a string of ransomware families over the years, including most recently LockBit.
A postmortem analysis of multiple incidents in which attackers eventually launched the latest version of LockBit ransomware (known variously as LockBit 3.0 or ‘LockBit Black’)
Symantec, a division of Broadcom Software, has observed threat actors targeting server machines in order to spread the LockBit ransomware threat throughout compromised networks.
We found connections between ShadowSyndicate infrastructure and Citrix Bleed attack infrastructure that spread Lockbit ransomware.
Ce groupe utilisait auparavant des ransomwares tiers (RedAlert, LockBit, Babuk).
In a real-world case, evidence was found that the threat actor, believed to be UAT-8099, used LockBit 3.0 Ransomware; after uploading a web shell, they attempted to gain control and manipulate SEO using Potato, AnyDesk, GotoHTTP, LCX, the NPS client (npc.Exe), BadIIS...
We investigated a recent LockBit extortion incident that occurred in Q3 2023... In September 2019, Cybereason found this hostname in old LockBit 2.0 extortions...
CYBLE identified the DragonForce ransomware binary as being based on LockBit 3.0 (Black) ransomware.
The attackers used a version of the popular LockBit 3.0 ransomware, compiled from publicly available source code, to encrypt the data.
The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.
Talos IR responded to Warlock, Babuk, and Kraken ransomware variants for the first time, while also responding to previously seen families Qilin and LockBit.
NullBulge is delivering LockBit ransomware payloads to their Async and Xworm victims as a later-stage infection.
During a recent investigation, our DFIR team discovered that LockBit Ransomware-as-a-Service (Raas) side-loads Cobalt Strike Beacon through a signed VMware xfer logs command line utility.
As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.
As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.
UNC3753 traces back to the now-defunct Conti ransomware gang, sharing overlaps with UNC2686, which ran BazarCall-style campaigns from 2021. The group deployed LockBit Black in 2022 but dropped ransomware entirely after that, focusing purely on data theft and extortion.
Impact T1486 Data Encrypted for Impact PhantomCore использовали LockBit 3.0 для шифрования трафика
Around November 2021, DEV-0243 started to deploy the LockBit 2.0 RaaS payload in their intrusions. ... In a notable shift ... DEV-0401 started deploying LockBit 2.0 ransomware payloads in April 2022.
CosmicBeetle, an immature ransomware threat actor using its own signature encryptor, ScRansom, and the leaked LockBit 3.0 builder, became an affiliate of RansomHub.
Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.
LockBit posted 163 victims in Q1 2026, climbing to fourth place globally.
...or generated using the leaked LockBit Black builder.
"In 2024, a member of Evil Corp was identified as an affiliate of the LockBit ransomware-as-a-service (RaaS) scheme."
The attackers used a version of the popular LockBit 3.0 ransomware, compiled from publicly available source code, to encrypt the data.
...delivering various ransomware payloads over the years, including ... LockBit ... ransomware...; ...DragonForce... using a variant of the leaked LockBit3.0 builder...
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
UNC2465, which used the Darkside and Lockbit ransomware...
Bl00Dy ... used open-source and leaked builders from other operators, including LockBit, Babuk and Conti. From September 2022, the group used the LockBit ransomware builder in its attacks... Similarly, the DragonForce ransomware binary was also revealed to have been likely generated using the LockBit Black builder.
...Bearlyfy that has used ransomware strains like LockBit 3.0 and Babuk...
The LockBit gang began its operation in September 2019 and was first known as “ABCD ransomware.” ... Over the next six months, LockBit worked on a new project, internally referred to as “LockBit Red,” and publicly known as “LockBit 2.0.” ... LockBit officially announced another major release ... LockBit Black (publicly known as LockBit 3.0).
Lockers such as Babuk and LockBit.
The ransomware strain observed in these incidents closely resembles LockBit 3.0 (LockBit Black).
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.