LockBit is a ransomware family and ransomware-as-a-service operation managed by the cybercriminal group tracked as GOLD MYSTIC. Emerging from ABCD ransomware in 2019 and adopting the LockBit name in 2020, it supplies affiliates with encryptors, negotiation facilities, a data-leak platform, and supporting tools. Its double-extortion model combines file encryption with threats to publish stolen information, although some affiliates conduct data-theft-only extortion. Victims span numerous countries and industries, including manufacturing, healthcare, transportation, government, and professional services.
LockBit targets Windows, Linux, and VMware ESXi systems; macOS samples have also been identified. Major generations include LockBit 2.0, LockBit 3.0, also called LockBit Black, and LockBit Green, which incorporates an encryptor based on leaked Conti source code. Supported behaviors vary by version and include terminating configured processes and services, disabling security software, deleting shadow copies, executing in Safe Mode, establishing persistence, clearing logs, and restricting access to Windows event channels. Affiliates steal data using the operation's StealBit tool or alternatives such as Rclone and MEGAsync, and deploy ransomware across endpoints and virtualization infrastructure.
Affiliate intrusion methods include stolen credentials, exposed remote-access services, phishing, spearphishing, drive-by compromise, SEO poisoning, vulnerability exploitation, and access purchased from initial-access brokers. LockBit affiliates have exploited Citrix Bleed, CVE-2023-4966, to obtain authentication session tokens and bypass multifactor authentication before further intrusion activity. The public leak of the LockBit 3.0 builder in September 2022 enabled unrelated actors to generate customized encryptors and decryptors; consequently, use of a LockBit-derived payload does not establish affiliation with its operators. International law enforcement disrupted LockBit infrastructure in February 2024, but the operation's decentralized affiliates and publicly available builder extend the threat beyond its central infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
LockBit affiliates have been documented exploiting CVE-2021-44228. The initial-access table also states that affiliates may exploit vulnerabilities such as Log4Shell in internet-facing systems.
The report's MITRE CONTEXT section lists CVE-2024-1708 under "Exploits Vulnerabilities" in its discussion of LockBit ransomware.
Based on secondary sources, the advisory identifies CVE-2023-27350, the PaperCut MF/NG improper access control vulnerability, among newer vulnerabilities exploited by LockBit affiliates.
In Incident R in late 2023, Secureworks incident responders observed an affiliate gain access to a network by exploiting the 'Citrix Bleed' buffer overflow vulnerability (CVE-2023-4966) in NetScaler ADC and NetScaler Gateway.
The advisory lists CVE-2020-1472, the NetLogon privilege escalation vulnerability, among CVEs that LockBit affiliates have been documented exploiting.
The report's MITRE CONTEXT section lists CVE-2024-1709 under "Exploits Vulnerabilities" in its discussion of LockBit ransomware.
CVE-2025-49704 (a code injection/remote code execution, or RCE, vulnerability). When chained together, these vulnerabilities allowed authorized attackers to gain remote code execution and access or alter sensitive information.
Based on secondary sources, the advisory notes that LockBit affiliates exploit newer vulnerabilities including CVE-2023-0669 in Fortra GoAnywhere Managed File Transfer.
LockBit affiliates have been documented exploiting CVE-2021-22986, described as an F5 BIG-IP and BIG-IQ Centralized Management iControl REST remote code execution vulnerability.
In July 2025, Microsoft disclosed active exploitation of on-premises SharePoint servers, targeting two critical vulnerabilities: CVE-2025-49706 (an improper authentication/spoofing flaw) and CVE-2025-49704 (a code injection/remote code execution, or RCE, vulnerability).
LockBit affiliates have been documented exploiting CVE-2019-0708, identified as a Microsoft Remote Desktop Services remote code execution vulnerability.
Sophos X-Ops recently observed unsuccessful attempted ransomware activity against customers. The attempt utilized CVE-2023-40044, in WS_FTP Server from Progress Software.
The advisory identifies CVE-2018-13379, a Fortinet FortiOS SSL VPN path traversal vulnerability, among CVEs exploited by LockBit affiliates.
The February 27, 2023 update reports exploitation of CVE-2022-36537 in ConnectWise R1Soft Server Backup Manager to deploy backdoors on hundreds of servers. Huntress demonstrated an exploit chain using the ZK authentication bypass to upload a backdoored JDBC driver, execute code as root, and execute commands on registered endpoints. | Use the REST API to trigger commands to registered agents to ultimately push the recently leaked Lockbit 3.0 ransomware to all downstream endpoints.
Attackers deploying Warlock were discovered exploiting the ToolShell zero-day vulnerability in Microsoft SharePoint (CVE-2025-53770) on July 19, 2025. Storm-2603 used the exploit to deploy Warlock and LockBit ransomware. | Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit.
The protection section lists MS.Windows.Server.NTLM.Relay.Spoofing (CVE-2021-36942) among IPS signatures for vulnerabilities reportedly exploited by LockBit ransomware threat actors. | LockBit uses a dual extortion tactic, demanding that victims pay a ransom to recover their files and not release the stolen information to the public.
The protection section lists MS.Exchange.Server.Autodiscover.Remote.Code.Execution (CVE-2021-34473) among IPS signatures for vulnerabilities reportedly exploited by LockBit ransomware threat actors. | LockBit uses a dual extortion tactic, demanding that victims pay a ransom to recover their files and not release the stolen information to the public.
The protection section lists MS.Exchange.Server.Common.Access.Token.Privilege.Elevation (CVE-2021-34523) among IPS signatures for vulnerabilities reportedly exploited by LockBit ransomware threat actors. | LockBit uses a dual extortion tactic, demanding that victims pay a ransom to recover their files and not release the stolen information to the public.
The protection section lists MS.Exchange.MailboxExportRequest.Arbitrary.File.Write (CVE-2021-31207) among IPS signatures for vulnerabilities reportedly exploited by LockBit ransomware threat actors. | LockBit uses a dual extortion tactic, demanding that victims pay a ransom to recover their files and not release the stolen information to the public.
Microsoft was able to identify the involvement of two ransomware gangs (CL0P and LockBit) who were exploiting the tracked CVE-2023-27350 and CVE-2023-27351.
Storm-2603 was observed attempting to steal MachineKeys using the SharePoint vulnerabilities and deploying Warlock and Lockbit ransomware.
42 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The group used the leaked LockBit builder in its attack but did not try to make a profit.
The group used the leaked LockBit builder in its attack but did not try to make a profit.
These samples were created using the leaked LockBit 3.0 builder, which other threat actors heavily abused to launch their own ransomware operations.
Вывод справки в командной строке оформлен в стиле LockBit, что подтверждает предположение о том, что разработчики GenieLocker изначально стремились создать похожую на LockBit альтернативу для проведения собственных операций.
Storm-2603 was using the exploit to deploy Warlock and another ransomware payload, LockBit.
LockBit operators are exploiting Citrix Bleed to establish persistence and pivot across networks during recent ransomware attacks.
37 distinct techniques documented for this family, organized by ATT&CK tactic.
abusing legitimate windows tools such as "net.exe", "taskkill.exe" and "wmic.exe" for reconnaissance and execution
LockBit 3.0 will send encrypted host and bot information to its command and control (C2) servers.
A new Group Policy Object (GPO) was created to launch and execute a Batch (BAT) file via a scheduled task.
1,272 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a participant in a ransomware alliance with DragonForce and Qilin intended to share tools and infrastructure and improve attack effectiveness. The article provides no specific details about its payload capabilities or victims.
Mentioned only as a ransomware operation from which Qilin absorbed affiliates; no LockBit activity or technical behavior is analyzed.
Named ransomware referenced through its associated group’s historical exploitation of the ProxyShell vulnerability chain. The article provides no payload details and does not connect LockBit to CVE-2026-96940.
Ransomware mentioned as a statistical comparison with Akira. It accounted for 6% of successful attacks investigated by Coveware in the second quarter of 2023.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.