GOLD MYSTIC is the financially motivated cybercriminal group operating the LockBit ransomware-as-a-service (RaaS) and data-extortion platform. Its ransomware operations began in mid-2019; it adopted the LockBit malware name in 2020 and began publishing victims on its leak site in September 2020. By December 2023, the platform had named more than 2,350 victims across 112 countries. Confirmed targets include Canada's SickKids children's hospital and the United Kingdom's Royal Mail. The operation uses a decentralized affiliate model, delegating ransom negotiations and payment handling to affiliates with limited operator oversight. Attacks include encryption combined with threats to publish stolen data, as well as data-theft-only extortion. GOLD MYSTIC developed the StealBit exfiltration tool and released LockBit 2.0 in June 2021 and Linux- and VMware ESXi-compatible variants in late 2021. Its LockBitSupp persona promoted access to the extortion platform for affiliates using other ransomware families and recruited affiliates from disrupted competing operations. LockBit affiliates obtain access through compromised credentials, exposed remote-access services, vulnerability exploitation, and malware delivery chains such as Gootloader. Observed techniques include exploitation of Citrix Bleed, CVE-2023-4966, to steal authenticated session tokens and bypass MFA; network and directory reconnaissance; credential theft; lateral movement through RDP and PsExec; persistence through remote-administration software; and automated ransomware distribution from domain controllers. Affiliates exfiltrate data using StealBit and third-party transfer tools, disable security software, impair recovery, clear logs, and encrypt VMware ESXi infrastructure to disrupt hosted virtual machines. GOLD MYSTIC representatives maintained communications with members of GOLD ULRICK and GOLD BLACKBURN, reflecting collaboration within the wider cybercriminal ecosystem rather than established common leadership. On February 19, 2024, the UK's National Crime Agency, the FBI, and international partners disrupted LockBit infrastructure, seized funds, and targeted associated individuals. The September 2022 leak of the LockBit 3.0 builder also enabled unrelated copycats, so LockBit-branded activity does not by itself establish affiliation with GOLD MYSTIC.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operates the LockBit RaaS ecosystem, enabling affiliates to conduct ransomware and data-theft extortion at scale, including encryption of Windows and VMware ESXi environments and leak-site based extortion.
Named as a separate threat group whose representatives frequently communicated with Stern and members of GOLD ULRICK and GOLD BLACKBURN.
Operates the LockBit RaaS ecosystem, supplying ransomware, data-exfiltration tooling, and leak-site infrastructure while delegating negotiations and payment handling to affiliates. Affiliates conduct encryption-based double extortion and data-theft-only extortion, with widely varying technical capabilities. The report examines 22 compromises investigated from July 2020 through January 2024 and the February 2024 law-enforcement disruption. It distinguishes genuine affiliate activity from independent copycats using leaked ransomware builders or LockBit branding.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.