LockBit grew from an early ABCD ransomware strain into one of the most prolific ransomware-as-a-service operations, combining fast multithreaded encryption, double extortion, and affiliate-driven intrusions against corporate victims worldwide. Researchers and incident reporting tied the group to tactics including UAC bypasses, shadow-copy deletion, log clearing, network-share encryption, and later campaigns using evasive multi-stage loaders, Safe Mode persistence, and password-protected payload delivery. The operation also recruited insiders for direct access to enterprise networks, soliciting VPN, RDP, and email credentials and offering large payouts to employees willing to run malware inside their organizations.
LockBit’s criminal ecosystem evolved alongside broader ransomware market shifts, with reporting linking it to affiliate churn, code overlap with other families, and adoption of a modified Conti-based payload branded as LockBit Green. By 2023, analysts reported infrastructure and leak-site reliability problems that frustrated affiliates, even as the gang remained tied to major incidents such as the Royal Mail attack. In 2024, Operation Cronos disrupted LockBit infrastructure and seized decryption keys, and U.S., U.K., and Australian authorities later sanctioned and charged Russian national Dmitry Yuryevich Khoroshev as the alleged leader, saying LockBit hit more than 2,500 victims in at least 120 countries, collected at least $500 million in ransom, and caused billions in wider losses.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
45 events from the most recent confirmed update back to the earliest known activity.
Lexfo published a technical reverse-engineering analysis of a LockBit sample recovered during an incident response case, describing a human-operated intrusion assisted by Cobalt Strike. The report disclosed details of LockBit's encryption workflow, including RSA- and AES-based key handling, registry storage, I/O completion port acceleration, shadow-copy deletion, and a method to recover dynamically built stack strings during analysis.
Ruslan Magomedovich Astamirov was charged in New Jersey in June 2023 for participating in the LockBit conspiracy.
In May 2023, U.S. authorities unsealed indictments against alleged LockBit affiliates Mikhail Matveev and Mikhail Vasiliev.
In March 2023, LockBit attacked aerospace manufacturer Maximum Industries and claimed to have stolen more than 3,000 engineering diagrams tied to SpaceX-related work.
On February 9, 2023, LockBit announced that it had released all stolen Royal Mail data on its leak site.
On February 6, 2023, LockBit published some Royal Mail data and gave the victim 50 hours to pay.
On 2023-02-01, Seqrite published a technical analysis of a LockBit Black attack chain describing SMB brute-force initial access, PsExec-based lateral movement, BAT-file changes to RDP and authentication settings, CMSTPLUA UAC bypass, and extensive anti-forensic actions. The report also documented the payload's required '-pass' key, shared-drive encryption behavior, and use of the '.zbzdbs59d' extension and updated ransom-note naming.
On January 12, 2023, Royal Mail entered LockBit's negotiation portal after a LockBit attack that encrypted systems and stole data.
In late January 2023, LockBit responded to discussion of the leaked builder and warned that modified builds could contain a universal decryption key or other malicious changes.
In December 2022, LockBit posted and then deleted a message indicating it planned to release an updated payload based on leaked Conti ransomware.
On 2022-11-30, Sophos published analysis of multiple LockBit 3.0 intrusions and reverse-engineering findings showing BlackMatter code overlap, optional 32-character password-gated execution, the ability to encrypt without full administrator privileges, and affiliate use of tools such as Backstab, Cobalt Strike, GMER, Netscan, Mimikatz, and PowerShell. The report also said leaked LockBit data showed developers experimenting with self-spreading via Windows Group Policy Objects and PsExec.
On 2022-07-25, Trend Micro published reverse-engineering findings showing that LockBit 3.0/LockBit Black shared multiple code patterns and capabilities with BlackMatter, including API hashing, trampoline-based API invocation, ThreadHideFromDebugger anti-debugging, WMI-based shadow copy deletion, and reflective DLL loading. The report also detailed LockBit 3.0's packed executable design, required -pass argument, configuration-driven behavior, Safe Mode execution, language-based exclusions, and options to encrypt network shares and Exchange mailboxes.
On 2022-07-20, Symantec reported LockBit attacks that used compromised Windows servers, especially domain controllers, to spread ransomware across enterprise networks via malicious Active Directory Group Policy. The report disclosed server-specific tradecraft including Defender-disabling policies, SYSVOL staging, forced GPUpdate execution, privilege escalation, UAC bypass, shadow copy deletion, event log clearing, and related indicators of compromise.
Sophos published an incident reconstruction of a LockBit attack on a regional U.S. government agency in which attackers maintained access for roughly five to six months before deploying ransomware. The report described exposed RDP initial access, administrator-level compromise, use of tools including ScreenConnect, AnyDesk, Mimikatz, LaZagne, and NLBrute, file exfiltration to Mega, repeated log wiping, and remediation by Sophos and the victim organization.
On 2022-02-04, the FBI, coordinated with DHS/CISA, issued FLASH CU-000162-MW detailing LockBit 2.0 tradecraft, indicators of compromise, and mitigations. The alert described affiliate-based operations, Stealbit-enabled data theft, Active Directory group-policy abuse, insider recruitment, and a Linux variant targeting VMware ESXi.
On 2021-09-21, Nozomi Networks Labs published a technical analysis of a BlackMatter ransomware sample associated with the attack on Iowa-based NEW Cooperative Inc. The report detailed the malware's encryption, anti-analysis methods, extracted configuration, C2 domains, claimed 1000 GB data theft, and similarities to DarkSide.
On 2021-09-05, Chuong Dong published a reverse-engineering analysis of BlackMatter ransomware v2.0. The publication disclosed technical details of the malware's behavior and implementation, constituting an earlier public technical analysis of BlackMatter than the later Nozomi report already in the timeline.
On 2021-08-11, LockBit announced on its deep web forum that it had infected Accenture. Accenture confirmed the attack and said the incident had no impact on its operations or systems; Cyble reported the gang allegedly stole about 6 TB of data and demanded $50 million.
On 2021-08-06, the Australian Cyber Security Centre warned of a sharp increase in LockBit ransomware attacks affecting Australian organizations across sectors including professional services, construction, manufacturing, retail, and food. The advisory said many LockBit 2.0 intrusions used Fortinet devices vulnerable to CVE-2018-13379 for initial access and warned of data-leak extortion against non-paying victims.
Cyble published technical analysis of a LockBit 2.0 Windows sample compiled on 2021-07-26, describing capabilities including Active Directory and LDAP discovery, remote GPUpdate execution, Windows Defender policy tampering, process killing, dllhost.exe injection, and spread via mounted and VMware shared folders. The report also noted use of StealBIT for exfiltration and tools such as Metasploit Framework and Cobalt Strike.
ID Ransomware saw a sharp increase in Babuk Locker submissions starting on June 29, 2021, tied to a new campaign using the leaked builder, the .babyk extension, and a low bitcoin demand.
LockBit announced the launch of its LockBit 2.0 ransomware-as-a-service operation in June 2021, including redesigned Tor sites and automated network-wide encryption via Group Policy.
Babuk shut down in April 2021 after law-enforcement pressure following the MPD incident and later shifted to a data-extortion model called PayLoad Bin.
In April 2021, Babuk threatened to expose police informants and other sensitive data stolen from the Washington, D.C. Metropolitan Police Department if a ransom was not paid.
A threat actor identified as Bassterlord reportedly disclosed a flaw in LockBit's one-time free decryption mechanism that could have allowed victims to obtain unlimited free decryptions from the payment portal. The report said the portal was offline that day, suggesting LockBit may already have been fixing the issue.
On 2020-10-21, Sophos published analysis of eight recent LockBit attacks that used obfuscated PowerShell, Google Sheets-hosted script retrieval, persistent backdoors, AMSI bypass attempts, and selective victim profiling before ransomware deployment. The report said operators spread LockBit filelessly over WMI from a compromised internal server and encrypted targeted systems within about five minutes while wiping logs and minimizing disk artifacts.
LockBit advertised its 'LockBit Cryptolocker Affiliate Program' on an underground forum in January, marking its ransomware-as-a-service push after the rebrand.
The U.S. Department of Justice unsealed a 26-count indictment charging Dmitry Yuryevich Khoroshev with leading and administering the LockBit ransomware group.
The United States, United Kingdom, and Australia sanctioned Dmitry Yuryevich Khoroshev as the alleged leader, developer, and administrator of LockBit.
After the FBI raid, LockBitSupp claimed the operation remained active and created new darknet sites promising to release data stolen from prior victims.
Law enforcement seized LockBit's darknet websites in 2024 and repurposed the victim-shaming site to publish press releases and free decryption tools for victims.
FortiGuard Labs observed a new LockBit campaign during December and January that used .img containers, staged scripts, Safe Mode persistence, and evasive tooling before deploying LockBit ransomware.
On 15 March 2022, LockBit 3.0, also called LockBit Black, emerged as a new version of the ransomware.
LockBit 2.0 began actively recruiting insiders to provide RDP, VPN, or corporate email access and promised million-dollar payouts to help breach company networks.
A variant identified by 15 July 2021 was named LockBit 2.0, also called LockBit Red.
A leaked Babuk ransomware builder was uploaded to VirusTotal, and soon afterward another threat actor began using it in a global campaign.
On 5 November 2020, Lock2Bits was reported rebranded to LuckyDay, using the .luckyday extension and the ransom note 'File Recovery.txt.'
In June 2020, LockBit and four other ransomware gangs announced a partnership branded as the Ransom Cartel.
On 12 May 2020, a related variant named Lock2Bits was identified using the .lock2bits extension.
In May 2020, the operators used both the clearnet domain lockbit-decryptor.com and the Tor site lockbitks2tvnmwk.onion for victim negotiations.
In April 2020, LockBit ransom notes began threatening to publish stolen private data such as financial records, client information, network diagrams, and passwords if victims did not pay.
The article states that victims in January 2020 included organizations or users in the United States, Germany, France, and China.
By January 2020, LockBit ransom notes directed victims to the Tor portal lockbitks2tvnmwk.onion instead of relying only on email-based contact.
On 30-31 December 2019, the operators updated the malware, adopted the LockBit name, switched to the .lockbit extension, and moved away from earlier abcd-themed email identities.
The ransomware family later known as LockBit began activity in mid-October 2019 under the name ABCD, named for its .abcd file extension.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
28 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcenews.sophos.com
Open sourcenews.sophos.com
Open sourcenews.sophos.com
Open sourcenews.sophos.com
Open sourcegithub.com
Open sourceid-ransomware.blogspot.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.