Description Summary
LockBit is one of the most prolific ransomware-as-a-service operations in history. Active since 2019 across LockBit 1.0, 2.0, 3.0 (LockBit Black) and a leaked Linux/ESXi build, it has affected thousands of organizations. It uses double extortion — exfiltrating data prior to encryption and publishing victims on its leak site if ransom is unpaid. In February 2024 an international law-enforcement operation ('Operation Cronos') seized core infrastructure, though affiliates and rebranded forks remain active.
Threat Actor
Operated by an actor publicly known as LockBitSupp, the group runs an affiliate program in which operators take ~20% of ransom proceeds while affiliates conduct intrusions. U.S. and U.K. authorities have indicted Russian national Dmitry Khoroshev as the alleged operator.
Technical Indicators
.lockbit / .HLJkNskOq (random 9-char string in 3.0)
AES-256 (file encryption) + RSA-2048 (key wrapping); LockBit 3.0 uses a Curve25519/Salsa20-derived scheme
Restore-My-Files.txt (2.0) / [random].README.txt (3.0)
Manufacturing, Professional services, Healthcare, Construction, Financial
September 2019
Active — LockBit 5.0 released September 2025 (post-Operation Cronos)
Global — heaviest impact in the United States, United Kingdom, France, Germany, India
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 3 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| T1620 | Reflective Code Loading | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 3 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| T1567.002 | Exfiltration via StealBit/Rclone/MEGA | |
| Impact x 4 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop | |
| T1486 | Data Encrypted for Impact (LockBit Black) |