LockBit 3.0 (LockBit Black) Ransomware

Description Summary

LockBit 3.0, also called LockBit Black, was released in June 2022 as a major rewrite of LockBit 2.0. It introduced the first ransomware bug-bounty program, anti-analysis improvements (BlackMatter-derived encryption), and a reworked leak site. The LockBit 3.0 builder was leaked in September 2022 and has since been used as the basis for many new ransomware families (LockBit Green, BlackMatter-derivatives, DragonForce).

Threat Actor

LockBit operators; numerous third-party reuses since the builder leak.

Technical Indicators

Encryption Extension
.HLJkNskOq (random 9-char string)
Encryption Algorithm
AES + RSA-2048 (BlackMatter-derived encryption module)
Ransom Note Name
<random>.README.txt
Targeted Industries
Manufacturing, Professional services, Healthcare, Government
First Seen
June 2022
Last Seen
Active (post-Operation Cronos)
Geographical Location
Global

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop