LockBit is a prolific Russian-speaking ransomware-as-a-service operation that emerged in the early 2020s and became one of the most active and widely recognized cybercriminal extortion groups of the decade. It operates through a core team that develops and maintains ransomware tooling and leak-site infrastructure while relying on affiliates to obtain access to victim networks, conduct intrusions, exfiltrate data, and deploy encryption at scale. Common aliases and branding variants include LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, and more recent references to LockBit 5.0; reporting also frequently refers to LockBit affiliates as a distinct operational layer within the broader ecosystem. LockBit has targeted organizations globally across government, healthcare, manufacturing, finance, education, telecommunications, logistics, and other sectors, generally in opportunistic campaigns rather than a single narrow vertical. The group is known for double-extortion operations in which data is stolen before encryption and victims are threatened with public exposure if they do not pay. Law-enforcement reporting has shown that victim data was retained on LockBit-controlled infrastructure even after some ransom payments, reinforcing long-standing concerns that payment does not reliably result in deletion of stolen information. Operationally, LockBit and its affiliates have used a broad range of initial access vectors typical of mature human-operated ransomware programs, including exploitation of edge-device and remote-access vulnerabilities, abuse of exposed RDP and VPN services, credential-based compromise, and purchased access from criminal intermediaries. Public reporting has specifically linked LockBit affiliates to exploitation of high-profile vulnerabilities such as CVE-2023-4966. Post-compromise behavior commonly includes lateral movement, privilege escalation, credential theft, defense evasion, data exfiltration, and enterprise-wide ransomware deployment. LockBit-linked activity has also been associated with the use of legitimate administrative and remote-access tooling, as well as common exfiltration utilities, reflecting a pragmatic tradecraft model centered on speed and scale. The group’s ecosystem has been resilient despite major disruption efforts. A 2024 law-enforcement takedown targeted LockBit infrastructure, but the broader affiliate model and surrounding criminal service providers enabled continued activity and reconstitution. LockBit has also depended on external enabling infrastructure, including bulletproof hosting providers that have been accused by governments of supporting LockBit operations alongside other ransomware groups. Sanctions and criminal actions against such providers have highlighted LockBit’s integration into a wider Russian cybercrime support environment. LockBit has been repeatedly cited as one of the most prolific ransomware groups of the early 2020s and has remained relevant in later reporting even as newer groups gained market share. Variants and affiliate clusters under the LockBit name have continued to appear in victim-leak reporting, and former LockBit affiliates have reportedly migrated to or collaborated with other ransomware programs. Overall, LockBit is best understood as a durable, affiliate-driven extortion enterprise rooted in the Russian-speaking cybercriminal ecosystem, notable for high operational tempo, broad victimology, repeated rebranding, and sustained impact despite international law-enforcement pressure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
46 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
Two vulnerabilities were fixed in the PaperCut Application Server that allows remote attackers to perform unauthenticated remote code execution and information disclosure: CVE-2023–27350 ... Unauthenticated remote code execution flaw impacting all PaperCut MF or NG versions 8.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... A PoC exploit for the RCE flaw was released... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
CVE-2023–27351 ... Unauthenticated information disclosure flaw impacting all PaperCut MF or NG versions 15.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
...LockBit ransomware group as they exploited a vulnerability known as ‘Citrix Bleed’ (CVE-2023-4966) during their attacks. LockBit leveraged this flaw to hijack authenticated sessions...
1 more CVE tied to this actor tracked in Mallory.
532 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Prolific ransomware group operating in the RaaS ecosystem and responsible for large numbers of attacks against businesses, hospitals, and government agencies.
Ransomware group listed among those targeting healthcare organizations in the EMEA region.
Named ransomware operation whose leaked administrative panel/database is central to the investigation because an ExtortionLord record appeared in the leaked panel data.
Mentioned only as a previously linked Russia-aligned threat actor in background context about RansomHouse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.