LockBit Ransomware

Description Summary

LockBit is one of the most prolific ransomware-as-a-service operations in history. Active since 2019 across LockBit 1.0, 2.0, 3.0 (LockBit Black) and a leaked Linux/ESXi build, it has affected thousands of organizations. It uses double extortion — exfiltrating data prior to encryption and publishing victims on its leak site if ransom is unpaid. In February 2024 an international law-enforcement operation ('Operation Cronos') seized core infrastructure, though affiliates and rebranded forks remain active.

Threat Actor

Operated by an actor publicly known as LockBitSupp, the group runs an affiliate program in which operators take ~20% of ransom proceeds while affiliates conduct intrusions. U.S. and U.K. authorities have indicted Russian national Dmitry Khoroshev as the alleged operator.

Technical Indicators

Encryption Extension
.lockbit / .HLJkNskOq (random 9-char string in 3.0)
Encryption Algorithm
AES-256 (file encryption) + RSA-2048 (key wrapping); LockBit 3.0 uses a Curve25519/Salsa20-derived scheme
Ransom Note Name
Restore-My-Files.txt (2.0) / [random].README.txt (3.0)
Targeted Industries
Manufacturing, Professional services, Healthcare, Construction, Financial
First Seen
September 2019
Last Seen
Active — LockBit 5.0 released September 2025 (post-Operation Cronos)
Geographical Location
Global — heaviest impact in the United States, United Kingdom, France, Germany, India

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 3 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
T1620 Reflective Code Loading
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 3 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
T1567.002 Exfiltration via StealBit/Rclone/MEGA
Impact x 4 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop
T1486 Data Encrypted for Impact (LockBit Black)