LockBit is a financially motivated ransomware-as-a-service operation active since early 2020, with roots in the ABCD ransomware observed in 2019. Its ecosystem comprises core developers and operators, who supply ransomware and extortion infrastructure, and affiliates, who select victims and conduct intrusions. Ransom proceeds have typically been divided between affiliates and operators on an 80/20 basis. Major ransomware generations include LockBit 2.0, also called LockBit Red; LockBit 3.0, also called LockBit Black; and LockBit Green, which incorporated encryption code derived from leaked Conti source code. LockBitSupp is the operation's public-facing representative. LockBit conducts double extortion by encrypting systems and threatening to publish stolen information, and also supports partners conducting data-theft-only extortion. Its infrastructure includes a data leak site, victim negotiation facilities, and the custom StealBit exfiltration tool. Victim pages use publication countdowns and stolen-data samples to pressure organizations into paying. Documented targets include Boeing in the United States, the Port of Lisbon Administration in Portugal, and a nonprofit targeted through a compromised managed service provider. Affiliates obtain initial access through phishing, exposed remote services, compromised credentials, purchased network access, and exploitation of public-facing applications. Documented exploitation includes Citrix Bleed, CVE-2023-4966; PaperCut vulnerabilities; and ConnectWise ScreenConnect vulnerabilities. Intrusions involve credential and session-token theft, persistence, lateral movement, and data exfiltration using StealBit, rclone, and legitimate file-transfer services. Defense-evasion behaviors include disabling security software, execution in Safe Mode, anti-analysis measures, and tampering with Windows event-channel permissions. Ransomware also deletes shadow copies to impair recovery. Established payloads target Windows, Linux, and VMware ESXi, while macOS samples have also been observed. The LockBit 3.0 builder was publicly leaked, enabling unrelated actors to generate customized encryptors and decryptors; consequently, use of LockBit-derived malware alone does not establish attribution to the operation. Law-enforcement disruption and a subsequent compromise of the group's infrastructure contributed to its reduced prominence in 2025.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
20 CVEs this actor has used in observed campaigns. 20 of them exploited in the wild.
The article lists CVE-2023-27350 among N-day vulnerabilities reportedly exploited by the LockBit ransomware group and identifies an available IPS signature.
The groups were able to exploit this vulnerability, successfully deploying the infamous TrueBot malware that had been used many months prior.
CVE-2018-13379 is listed as reportedly exploited by LockBit; the article states that patches are available and lists a FortiOS SSL VPN IPS signature.
The article lists CVE-2019-0708 among vulnerabilities reportedly exploited by LockBit and provides an associated Windows RDP IPS signature.
CVE-2020-1472 appears among vulnerabilities reportedly exploited by LockBit; the article states patches are available and identifies a Netlogon IPS signature.
15 more CVEs tied to this actor tracked in Mallory.
801 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a participant in a ransomware alliance with DragonForce and Qilin intended to improve attack effectiveness through shared tools and infrastructure. No involvement in the arrest or investigated attacks is specified.
Mentioned as a comparison explaining why an extortion victim demanded proof of data destruction. The article cites LockBit's failure to delete data belonging to victims who paid, but does not connect LockBit operationally to Silent Ransom Group.
Ranked among the most active actors in the analyzed ransomware and data-extortion dataset. The article does not identify specific LockBit victims or operational methods.
The report attributes a ransomware attack against Capital Bank SA in Haiti to lockbit5. The reported breach occurred on October 4, 2026, at 22:13 UTC and was discovered on October 8, 2026, at 03:33 UTC. No technical evidence or additional attribution details are provided.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.