LockBit is a prolific financially motivated ransomware-as-a-service operation that emerged in 2019 and became one of the most active and impactful cybercriminal groups globally. It is widely tracked under aliases including LockBit, LockBit 2.0, LockBit Black, LockBit 3.0, LockBit Green, LockBit 4.0, LockBit 5.0, LockBit Group, LockBit Gang, and LockBitSupp. The operation is commonly assessed as Russia-linked or operating from the Russian-speaking cybercrime ecosystem, consistent with the broader ransomware affiliate model prevalent in that environment. LockBit operates a multi-affiliate extortion model in which core administrators maintain the ransomware platform, leak infrastructure, and branding while affiliates conduct intrusions against victim organizations. The group is known for double-extortion tactics, combining data theft with encryption and threats to publish stolen information if ransom demands are not met. It has targeted a wide range of sectors, including business services, government, healthcare, education, finance, and critical services, with victims concentrated heavily in the United States but spanning multiple regions. By confirmed victim counts, LockBit has been one of the most successful ransomware operations of the modern era and has been described as the all-time leader in verified attacks since 2019, with more than 500 confirmed victims. Despite sustained law-enforcement pressure, sanctions, and infrastructure disruption, the brand has remained active through multiple iterations and rebrands, including recent variants tracked as LockBit 5.0. Operationally, LockBit and its affiliates have been associated with common enterprise intrusion tradecraft seen across major ransomware families. Reported techniques include credential theft using NirSoft utilities and Mimikatz, lateral movement with PsExec, use of legitimate remote administration tools, privilege escalation, defense evasion, and pre-encryption data exfiltration. The group has also been linked to the broader cybercrime enablement ecosystem, including use of bulletproof hosting providers that allegedly supported LockBit operations alongside other ransomware groups. LockBit has been connected to several high-profile extortion incidents, including the 2021 attack on Accenture in which the group claimed large-scale data theft and issued a major ransom demand. LockBit branding has also been influential enough that other actors have imitated its naming conventions, particularly the LockBitSupp persona, although branding similarity alone does not establish operational ties. The group’s longevity, affiliate scale, and repeated versioning reflect a mature criminal enterprise rather than a single intrusion set. LockBit should be understood as both a ransomware family and an organized extortion ecosystem composed of administrators, affiliates, and supporting service providers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
Two vulnerabilities were fixed in the PaperCut Application Server that allows remote attackers to perform unauthenticated remote code execution and information disclosure: CVE-2023–27350 ... Unauthenticated remote code execution flaw impacting all PaperCut MF or NG versions 8.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... A PoC exploit for the RCE flaw was released... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
CVE-2023–27351 ... Unauthenticated information disclosure flaw impacting all PaperCut MF or NG versions 15.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
...LockBit ransomware group as they exploited a vulnerability known as ‘Citrix Bleed’ (CVE-2023-4966) during their attacks. LockBit leveraged this flaw to hijack authenticated sessions...
323 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the ransomware operations facilitated by Media Land LLC.
Named as a ransomware group that used Media Land and ML Cloud bulletproof hosting services.
Named as one of the ransomware groups that allegedly used Media Land and ML.Cloud bulletproof hosting infrastructure.
A ransomware group whose activity increased during the reporting period, ranking as the third most prevalent group in June.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.