🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
LOCKBIT

/actor/lockbit/  ·  0 intel reports

Year Established
2019
Attribution
Russia (Suspected)
Motivation
Financial
Modus Operandi (MO)
RaaS, most prolific ransomware of its era, aggressive affiliate model, automated propagation
Primary Aliases
LockBit 2.0, LockBit 3.0, LockBit Black, ABCD Ransomware (early)

LockBit was the world's most prolific and damaging ransomware operation for multiple consecutive years between 2022 and 2024, responsible for more ransomware attacks than any other group during this period according to multiple cybersecurity firm reports and government advisories. Operating as a highly sophisticated Ransomware-as-a-Service (RaaS) platform, LockBit's success stemmed from aggressive affiliate recruitment, competitive revenue-sharing (affiliates received up to 80% of ransoms), and continuous technical innovation in their ransomware payload.

The group's ransomware evolved through multiple generations , LockBit 2.0 introduced automated domain propagation enabling rapid network-wide encryption without manual operator intervention; LockBit 3.0 (LockBit Black) incorporated code from the leaked Blackmatter ransomware and introduced an unprecedented bug bounty program offering cryptocurrency rewards to security researchers who identified vulnerabilities in their ransomware , a surreal application of legitimate security industry practices to criminal enterprise.

LockBit's victim list encompasses thousands of organisations globally across virtually every sector, including Boeing, the UK Royal Mail, the Industrial and Commercial Bank of China (ICBC), the City of Oakland, Ion Trading Technologies (disrupting global derivatives markets), and Fulton County Georgia government systems. Their attacks against critical financial infrastructure caused cascading disruptions to global financial markets, demonstrating ransomware's capacity for systemic economic impact.

In February 2024, a coordinated law enforcement operation (Operation Cronos) led by the UK National Crime Agency seized LockBit's infrastructure, admin panel, affiliate accounts, and cryptocurrency holdings , temporarily disrupting operations. However, LockBit's administrator (known as "LockBitSupp") announced a resumption of operations within days, highlighting the extreme difficulty of permanently dismantling distributed, financially resilient criminal organisations through infrastructure seizure alone.

Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to LockBit requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles