> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
LOCKBIT
/actor/lockbit/ · 0 intel reports
LockBit was the world's most prolific and damaging ransomware operation for multiple consecutive years between 2022 and 2024, responsible for more ransomware attacks than any other group during this period according to multiple cybersecurity firm reports and government advisories. Operating as a highly sophisticated Ransomware-as-a-Service (RaaS) platform, LockBit's success stemmed from aggressive affiliate recruitment, competitive revenue-sharing (affiliates received up to 80% of ransoms), and continuous technical innovation in their ransomware payload.
The group's ransomware evolved through multiple generations , LockBit 2.0 introduced automated domain propagation enabling rapid network-wide encryption without manual operator intervention; LockBit 3.0 (LockBit Black) incorporated code from the leaked Blackmatter ransomware and introduced an unprecedented bug bounty program offering cryptocurrency rewards to security researchers who identified vulnerabilities in their ransomware , a surreal application of legitimate security industry practices to criminal enterprise.
LockBit's victim list encompasses thousands of organisations globally across virtually every sector, including Boeing, the UK Royal Mail, the Industrial and Commercial Bank of China (ICBC), the City of Oakland, Ion Trading Technologies (disrupting global derivatives markets), and Fulton County Georgia government systems. Their attacks against critical financial infrastructure caused cascading disruptions to global financial markets, demonstrating ransomware's capacity for systemic economic impact.
In February 2024, a coordinated law enforcement operation (Operation Cronos) led by the UK National Crime Agency seized LockBit's infrastructure, admin panel, affiliate accounts, and cryptocurrency holdings , temporarily disrupting operations. However, LockBit's administrator (known as "LockBitSupp") announced a resumption of operations within days, highlighting the extreme difficulty of permanently dismantling distributed, financially resilient criminal organisations through infrastructure seizure alone.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to LockBit requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.