LockBit is a financially motivated ransomware-as-a-service operation that has been active since around 2019 and has been one of the most prolific leak-site extortion groups globally. It is widely known through versions including LockBit 2.0 and LockBit 3.0, the latter also referred to as LockBit Black. The operation uses an affiliate model in which core operators maintain the ransomware platform and extortion infrastructure while affiliates conduct intrusions and victim negotiations. LockBit is associated with double-extortion activity, combining file encryption with threats to publish stolen data on a leak site. Its leak infrastructure has used countdown-based pressure tactics, and the group has remained highly active across multiple years despite operational disruption, including the February 2024 law-enforcement action known as Operation Cronos, after which it rapidly re-established leak and mirror sites. Technical analysis of LockBit 2.0 shows a mature Windows ransomware capability set focused on speed, scale, and operational resilience. Observed behaviors include anti-debugging and string/API obfuscation, privilege escalation through UAC bypass, persistence via autorun mechanisms, process and service termination, encryption of local and network-accessible resources, forced mounting of hidden volumes, deletion of shadow copies and event logs, ransom-note deployment through multiple formats, printer-based coercion, and self-deletion to hinder forensic recovery. LockBit has also demonstrated domain-wide propagation capability through Group Policy when executed with sufficient privileges on a domain controller. The malware has used partial encryption and hardware-accelerated cryptography to maximize speed. The group has exploited publicly exposed enterprise technologies and vulnerabilities for intrusion and has been linked to abuse of legitimate remote management tools. Reporting also places LockBit in the broader ransomware affiliate ecosystem, including overlap or possible cooperation with actors such as Karakurt and evidence of affiliate recruitment or migration involving other major ransomware groups. LockBit has publicly claimed restrictions on certain victim categories, but observed victimization has still included healthcare-related organizations and a wide range of commercial and public-sector targets worldwide. Known aliases and related naming variants include LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, LockBitSupp, and numerous affiliate-tagged references.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
Two vulnerabilities were fixed in the PaperCut Application Server that allows remote attackers to perform unauthenticated remote code execution and information disclosure: CVE-2023–27350 ... Unauthenticated remote code execution flaw impacting all PaperCut MF or NG versions 8.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... A PoC exploit for the RCE flaw was released... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
CVE-2023–27351 ... Unauthenticated information disclosure flaw impacting all PaperCut MF or NG versions 15.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
...LockBit ransomware group as they exploited a vulnerability known as ‘Citrix Bleed’ (CVE-2023-4966) during their attacks. LockBit leveraged this flaw to hijack authenticated sessions...
1 more CVE tied to this actor tracked in Mallory.
710 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a ransomware attack against actua.fr / Groupe Actua, a recruitment and temporary staffing agency in France.
Conducting a ransomware attack against dupouy-associes.fr, an accounting services organization in France.
Conducting a ransomware attack against agricolagalbusera.it, an agriculture and food production organization in Italy.
Conducting a ransomware attack against TECOSIM, a technology corporation in Germany.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.