Secureworks examined 22 LockBit compromises spanning July 2020 through January 2024, documenting diverse affiliate techniques behind one of the largest ransomware-as-a-service operations. Operated by GOLD MYSTIC, LockBit's leak site named more than 2,350 victims across 112 countries through the end of 2023. On February 19, 2024, the UK's National Crime Agency, the FBI, and international partners disrupted its infrastructure, seized funds, and targeted individuals associated with the operation.
The review identified attacks involving stolen credentials, vulnerability exploitation, automated ransomware deployment, VMware ESXi encryption, and data theft-only extortion. Affiliates controlled negotiations and payments, allowing rapid growth but producing inconsistent outcomes and limiting operator oversight. Affiliate movement between ransomware schemes and copycat use of LockBit's brand underscore that infrastructure takedowns do not necessarily eliminate the attackers. Secureworks recommends securing initial-access pathways, detecting precursor activity, hardening virtualization infrastructure, preserving forensic evidence, and maintaining isolated backups.

TTPs, infrastructure, and targeting history in one profile.
27 events from the most recent confirmed update back to the earliest known activity.
Explanatory tiles replaced the seizure notice on LockBit's seized site following the law enforcement disruption.
At approximately 4:00 p.m. EST, the UK's National Crime Agency, the FBI, and international partners began disrupting LockBit infrastructure. Authorities seized its leak site and mirrors, notified affiliates through the administration panel, seized funds, targeted associated individuals, and announced further sanctions.
The FBI reported affiliates deploying multiple ransomware variants in September 2023.
Canada's Communications Security Establishment claimed that LockBit accounted for 44% of global ransomware attacks.
Later in 2023, LockBitSupp invited ALPHV/BlackCat and NoEscape affiliates to join LockBit following an infrastructure disruption and an exit scam, respectively.
In Incident T in late 2023, a victim received a LockBit ransom note after data exfiltration and a Hunters International demand approximately two weeks later. Investigators observed neither encryption nor evidence of separate attackers.
In Incident R in late 2023, a LockBit affiliate exploited CVE-2023-4966 to obtain NetScaler session tokens capable of bypassing MFA. The attacker established persistent access through Zoho Assist, stole data using MEGAsync, and distributed ransom notes without deploying ransomware.
In Incident O in mid-2023, an attacker used two domain controllers to distribute LockBit across multiple hosts approximately four and a half hours after the first observed malicious activity. The attacker staged company files and uninstalled Cisco Secure Endpoint before encryption, but investigators could not establish whether exfiltration occurred.
GOLD DUPONT, which distributes RansomExx, attacked the Incident A organization through a Citrix entry point similar to the one used in its 2020 compromise. Secureworks considered substantial differences in tradecraft evidence against the same affiliate being responsible.
In Incident M in early 2023, a LockBit affiliate entered through a Fortinet VPN and encrypted an ESXi host containing 25 virtual machines. Files on three Windows domain controllers were also encrypted.
In early 2023, LockBitSupp stated that affiliates could use other ransomware variants provided they used LockBit's extortion platform.
A LockBit affiliate attacked Toronto's SickKids children's hospital in December 2022. LockBit operators subsequently apologized, provided a free decryptor, and claimed to expel the attacker.
An extortion scam using LockBit branding demanded 25 bitcoins. No subsequent encryption or data publication was observed.
The LockBit 3.0 builder leaked in September 2022, subsequently enabling copycat use of the ransomware.
In Incident H in late 2022, an attacker compromised VMware Horizon and deployed LockBit 3.0, followed approximately 12 hours later by ALPHV ransomware. Secureworks assessed that the same affiliate was more likely responsible, although attribution remained inconclusive.
In Incident J in late 2022, an attacker used a compromised domain administrator account, created an account with domain and ESX administrative privileges, and connected to three ESXi hosts through MobaXterm over SSH. Some virtual machines were encrypted, although investigators did not establish the encryption mechanism.
In Incident G in early 2022, an administrator downloaded cracked software bundled with RedLine, and a LockBit affiliate likely acquired the stolen credentials and accessed a single-factor-protected Citrix App server about a week later. The attacker exfiltrated data and deployed LockBit 2.0 through PsExec batch scripts; stolen data was subsequently published after nonpayment.
GOLD MYSTIC launched LockBit 2.0 after approximately six months of apparent inactivity, claiming easier operation and faster encryption. Victim listings subsequently increased substantially.
GOLD MYSTIC released Linux- and VMware ESXi-compatible LockBit variants in late 2021, enabling affiliates to target virtualization hosts.
Incident C in mid-2021 began with a malicious JavaScript download from a compromised WordPress site and progressed through Gootloader, PowerShell, and Cobalt Strike Beacon to LockBit deployment and print bombing. Infrastructure links suggested involvement by a former REvil affiliate.
GOLD MYSTIC first listed victims on its ransomware leak site in September 2020.
In Incident A in mid-2020, an attacker likely used compromised credentials to access a Citrix server, installed AnyPlace Control, and executed LockBit. The ransomware established persistence and attempted to impair recovery and clear logs, but encrypted no files.
GOLD MYSTIC adopted LockBit as the name of its ransomware malware.
GOLD MYSTIC began operating a ransomware scheme that subsequently adopted the LockBit name.
In Incident Q, a LockBit affiliate likely abused VPN credentials, exfiltrated data, and encrypted all virtual machines in the affected environment.
In Incident K, an attacker used LockBit 3.0 with atypical email-based payment contact after the ransomware's builder leaked. Secureworks identified the incident as an example of copycat abuse of LockBit branding.
LockBit operators initially denied and later acknowledged an affiliate attack against Royal Mail.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.