LockBit is a ransomware family and ransomware-as-a-service operation that became one of the most prolific extortion threats of the early 2020s. Active from 2020 through 2024 as a dominant criminal enterprise, it used an affiliate model in which operators supplied ransomware tooling and infrastructure to partners who conducted intrusions and deployed the encryptor against victim environments worldwide. LockBit was responsible for attacks against thousands of organizations across many sectors and countries, and it generated hundreds of millions of dollars in ransom payments.
LockBit is best known for file encryption and extortion. Public reporting also established that the operation retained stolen victim data despite promises to delete it after payment, demonstrating a double-extortion component and unreliable post-payment behavior. Variants associated with LockBit 3 were widely circulated, and the 2022 leak of the LockBit builder enabled third parties to generate custom versions, lowering the barrier to reuse by unrelated actors. Incident reporting from 2025 and 2026 shows continued use of custom LockBit 3 builds by financially motivated intruders after obtaining privileged access in victim networks.
The malware and its ecosystem have been associated with Windows attacks for years, and later reporting also described cross-platform capability spanning Linux and VMware ESXi in post-Cronos “LockBit 5.0” activity. Observed intrusions involving LockBit deployments relied heavily on hands-on-keyboard tradecraft rather than autonomous worming, including use of valid accounts for access, manual lateral movement, remote administration tooling such as PsExec, and scripts to weaken endpoint protections and enable remote access before encryption. In at least one documented case, investigators found no evidence of data exfiltration despite successful encryption, indicating that affiliate behavior varied by intrusion.
In February 2024, Operation Cronos, a multinational law-enforcement action, disrupted LockBit by seizing core infrastructure including its leak site, control systems, and source code, and by undermining affiliate trust in the brand. The operation significantly degraded LockBit’s credibility and attack volume, although later reporting described attempts to revive the brand under a new version label. LockBit remains one of the most recognizable ransomware names because of its scale, affiliate-driven operating model, and lasting influence on the ransomware ecosystem.
In a real-world case, evidence was found that the threat actor, believed to be UAT-8099, used LockBit 3.0 Ransomware; after uploading a web shell, they attempted to gain control and manipulate SEO using Potato, AnyDesk, GotoHTTP, LCX, the NPS client (npc.Exe), BadIIS...
The LockBit ransomware group, active since around 2019... In December 2024, the group announced its newest ransomware version, “Lockbit 4”. Lockbit 4 has two versions, Black and Green, In this article we will analyze the green version.
We investigated a recent LockBit extortion incident that occurred in Q3 2023... In September 2019, Cybereason found this hostname in old LockBit 2.0 extortions...
The CyberVolk collective is a prime example of how readily threat actors can access and deploy dangerous ransomware builders such as AzzaSec, Diamond, LockBit, Chaos and others.
Talos IR responded to Warlock, Babuk, and Kraken ransomware variants for the first time, while also responding to previously seen families Qilin and LockBit.
During a recent investigation, our DFIR team discovered that LockBit Ransomware-as-a-Service (Raas) side-loads Cobalt Strike Beacon through a signed VMware xfer logs command line utility.
UNC3753 traces back to the now-defunct Conti ransomware gang, sharing overlaps with UNC2686, which ran BazarCall-style campaigns from 2021. The group deployed LockBit Black in 2022 but dropped ransomware entirely after that, focusing purely on data theft and extortion.
The GOLD MYSTIC threat group has operated the LockBit name-and-shame ransomware-as-a-service (RaaS) scheme since mid-2019, exploiting unauthorized access to thousands of organizations to deploy ransomware and steal data to facilitate the extortion of victims.
Around November 2021, DEV-0243 started to deploy the LockBit 2.0 RaaS payload in their intrusions. ... In a notable shift ... DEV-0401 started deploying LockBit 2.0 ransomware payloads in April 2022.
Around November 2021, DEV-0243 started to deploy the LockBit 2.0 RaaS payload in their intrusions. ... In a notable shift ... DEV-0401 started deploying LockBit 2.0 ransomware payloads in April 2022.
CosmicBeetle, an immature ransomware threat actor using its own signature encryptor, ScRansom, and the leaked LockBit 3.0 builder, became an affiliate of RansomHub.
According to their posts on Exploit, Wazawaka has worked with at least two different ransomware affiliate programs, including LockBit. Wazawaka said LockBit had paid him roughly $500,000 in commissions for the six months leading up to September 2020.
Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.
The vulnerability was attributed to Lace Tempest, a Cl0p ransomware affiliate, in April 2023, used in campaigns delivering Cl0p and LockBit ransomware payloads.
...delivering various ransomware payloads over the years, including ... LockBit ... ransomware...; ...DragonForce... using a variant of the leaked LockBit3.0 builder...
Bl00Dy ... used open-source and leaked builders from other operators, including LockBit, Babuk and Conti. From September 2022, the group used the LockBit ransomware builder in its attacks... Similarly, the DragonForce ransomware binary was also revealed to have been likely generated using the LockBit Black builder.
The LockBit gang began its operation in September 2019 and was first known as “ABCD ransomware.” ... Over the next six months, LockBit worked on a new project, internally referred to as “LockBit Red,” and publicly known as “LockBit 2.0.” ... LockBit officially announced another major release ... LockBit Black (publicly known as LockBit 3.0).
The LockBit gang began its operation in September 2019 and was first known as “ABCD ransomware.” ... Over the next six months, LockBit worked on a new project, internally referred to as “LockBit Red,” and publicly known as “LockBit 2.0.” ... LockBit officially announced another major release ... LockBit Black (publicly known as LockBit 3.0).
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.