LockBit is a prominent cybercrime ransomware-as-a-service operation tracked by some vendors as Syrphid. Active since 2019, it has operated through a core team and a network of affiliates and became one of the most prolific financially motivated ransomware ecosystems. The operation is associated with large-scale extortion activity and was disrupted by law-enforcement actions in 2024; public reporting has also linked alleged leader Dimitry Khoroshev, also known as LockBitSupp, to the group. The leak of the LockBit 3.0 builder increased the likelihood of reuse by actors beyond the original operators. LockBit intrusions have involved prolonged pre-encryption access, use of remote access tools for initial footholds, and extensive post-compromise activity before ransomware deployment. Observed tradecraft includes privilege escalation, UAC bypass, credential and token theft, Kerberos ticket theft, discovery using native Windows utilities, lateral movement, and defense evasion. The group has used DLL sideloading and masquerading to blend malicious components with legitimate signed executables, and has renamed payloads and placed them in trusted-looking locations to reduce suspicion. A notable LockBit technique on Windows enterprise networks is propagation via Active Directory Group Policy, especially from compromised domain controllers. In such cases, the ransomware can create malicious policies to disable Microsoft Defender protections, stop services and processes, copy itself to shared domain locations, and force policy updates across domain-joined systems. Observed behavior also includes anti-debugging checks, language-based self-termination to avoid systems in Russia and nearby countries, process termination, service disruption affecting backup, database, and mail systems, shadow copy deletion, recovery inhibition, event log clearing, and file encryption followed by ransom-note presentation. LockBit is best characterized as a financially motivated extortion actor using ransomware for impact and monetization. Its operational model, affiliate structure, and repeated use of enterprise-wide deployment mechanisms have made it one of the most consequential ransomware threats of its era.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operators behind LockBit, using affiliates to deploy ransomware on victim networks and, in the observed case, spreading via Active Directory Group Policy from server/domain controller systems.
Identified in the content as the cybercrime group operating the LockBit RaaS, associated with large-scale extortion activity since 2019 and disrupted by law enforcement operations in 2024 (including indictment of alleged ringleader Dimitry Khoroshev / 'LockBitSupp').
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.