Overview
Platforms:
Windows · Linux · macOS · ESXi
Variants:
LockBit Red · LockBit Black · LockBit Green · LockBit 3.0 · LockBit 2.0
Extensions:
.abcd · .lockbit
ATT&CK software:
StealBit · Angler · Pikabot
Initial access:
Exploit Public-Facing Application · Valid Accounts · External Remote Services
Top countries:
US · GB · FR · DE · CA
Observed sectors:
Manufacturing · Professional Services · Healthcare · Technology · Financial Services
Tracked victims:
3,231
Attribution
Dmitry Yuryevich Khoroshev (LockBitSupp)
VERIFIED
Operator identity
LockBit
VERIFIED
Group identity
Affiliates
Mikhail Vasiliev
Russian-Canadian national who pleaded guilty in U.S. federal court to charges related to his role in the LockBit ransomware conspiracy.
Ruslan Astamirov
Russian national charged by the U.S. Department of Justice for his involvement in the LockBit ransomware conspiracy; indictment proceedings active.
Activity
Initial Access
Exploitation of public-facing applications
LockBit affiliates have exploited internet-facing services and vulnerabilities to obtain initial access.
Remote services and valid accounts
LockBit affiliates have used compromised credentials, VPN access and RDP for initial access.
Phishing
Phishing and spearphishing have been documented as initial-access techniques used by LockBit affiliates.
Recent Observations
Continued LockBit 5.0 activity
September 2026
Leak-site activity
LockBit 5.0 continued publishing new victim claims in September 2026.
LockBit 5.0 affiliate rebuilding
March 2026
Operational activity
LockBit 5.0 showed renewed growth in victim postings during Q1 2026 as the operation rebuilt its affiliate ecosystem.
LockBit 5.0 launch
September 2025
Operational change
LockBit 5.0 was launched on underground forums as the next generation of the LockBit RaaS operation.
TTPs
ATT&CK coverage:
9 techniques
T1190
Exploit Public-Facing Application
VERIFIEDAffiliates leverage vulnerabilities in edge devices and public applications such as Citrix, Fortinet, and VPN gateways for initial entry.
T1078
Valid Accounts
VERIFIEDUse of stolen credentials purchased from initial access brokers or captured via phishing to gain access to victim environments.
T1133
External Remote Services
VERIFIEDDeployment of tools to facilitate RDP access or exploitation of existing remote management infrastructure.
Show more TTPs (6)
T1059.003
Windows Command Shell
VERIFIEDExtensive use of command-line interfaces and batch scripts for reconnaissance, lateral movement, and payload execution.
T1484.001
Group Policy Modification
VERIFIEDModification of Group Policy Objects to push malicious binaries or disable security settings across the domain.
T1003.001
LSASS Memory
VERIFIEDUse of credential dumping tools like Mimikatz or ProcDump to extract credentials from memory.
T1562.001
Impair Defenses: Disable or Modify Tools
VERIFIEDAffiliates frequently attempt to disable or uninstall antivirus and EDR agents before executing the final encryption payload.
T1490
Inhibit System Recovery
VERIFIEDExecution of commands to delete Volume Shadow Copies and clear Windows Event Logs to hinder forensic recovery.
T1486
Data Encrypted for Impact
VERIFIEDExecution of LockBit ransomware binaries (e.g., LockBit 3.0/Black) to encrypt data across Windows, Linux, and ESXi environments.
Victims
Itaguaí Construções Navais (ICN)
CLAIMED
Manufacturing organization in BR.
Verbandsgemeinde Rhein-Nahe
CLAIMED
Government organization in DE.
Hanover Police Department
CLAIMED
Government organization in US.
Grey High School
CLAIMED
Education organization in ZA.
Graphique de France
CLAIMED
Manufacturing organization in US.
Show more victims (8)
Crystal D
CLAIMED
Manufacturing organization in US.
AC Investment Management, LLC
CLAIMED
Financial Services organization in US.
OYO Hotel & Casinos Las Vegas
CLAIMED
Organization in US.
Topackt IT Solutions GmbH
CLAIMED
Technology organization in DE.
Equinox
CLAIMED
Healthcare organization in US.
Evolve Bank & Trust
CONFIRMED
Financial Services organization in US.
Saint Anthony Hospital
CONFIRMED
Healthcare organization in US.
Taiwan Semiconductor Manufacturing Company
CONFIRMED
Manufacturing organization in TW.
CVEs
Exploited by LockBit affiliates for initial access to Fortinet FortiOS SSL VPN gateways.
Associated since:
2020
CVE-2023-3519 has been widely exploited against Citrix ADC and Gateway appliances, but the currently attached source does not directly substantiate exploitation by LockBit affiliates.
Citrix Bleed vulnerability identified as being leveraged by LockBit 3.0 affiliates for initial access.
Associated since:
November 2023
Infrastructure
LockBit 3.0 leak site
Primary platform for publishing victim data and double-extortion claims under the LockBit 3.0 (Black) branding.
ONLINE
Last checked:
May 15, 2024
Affiliate portal
Infrastructure used to manage affiliate registration, target negotiation, and ransomware binary generation.
Timeline
2024-02-20
Operation Cronos
A multi-national law enforcement operation led by the UK NCA and FBI resulted in the seizure of LockBit infrastructure and the compromise of internal administrative panels.
2022-03-01
LockBit 3.0 emergence
LockBit 3.0, often referred to as LockBit Black, was launched, incorporating new obfuscation methods and a bug bounty program.
2021-06-01
LockBit 2.0 release
LockBit transitioned to version 2.0, introducing the StealBit exfiltration tool and an expanded RaaS program.
Show more events (1)
2019-09-01
ABCD ransomware emergence
The ransomware variant initially referred to as ABCD, the predecessor to LockBit, was first identified in the wild.
Sources
Show more sources (61)
NCA leads international investigation into LockBit
National Crime Agency
Q1 2026 Ransomware Landscape
Check Point Research
Ransomware Data Leak Site Monitoring
RansomwareLive
#StopRansomware: LockBit 3.0
FBI / CISA
LockBit Ransomware Operations
Mandiant
National Crime Agency leads major disruption of LockBit ransomware group
National Crime Agency
Russian-Canadian National Pleads Guilty to Role in LockBit Ransomware Conspiracy
U.S. Department of Justice
Russian National Charged for Role in LockBit Ransomware Conspiracy
U.S. Department of Justice
LockBit leader identified as Dmitry Yuryevich Khoroshev
National Crime Agency
UK leads global operation to take down LockBit
National Crime Agency
International investigation disrupts the world's most harmful cyber crime group
National Crime Agency (NCA)
National Crime Agency Lockbit Operation Cronos Summary
National Crime Agency
City of Wichita hit by LockBit ransomware
BleepingComputer
National Crime Agency Lockbit disruption statement
National Crime Agency
District of New Jersey LockBit case summary
U.S. Department of Justice
National Strategic Assessment 2025
National Crime Agency
U.S. and U.K. Disrupt LockBit Ransomware Variant
U.S. Department of Justice
FBI Cyber Deputy Assistant Director remarks on LockBit disruption
Federal Bureau of Investigation
FBI Cyber Assistant Director remarks at the 2024 Boston Conference on Cyber Security
Federal Bureau of Investigation
LockBit says they stole data in London Drugs ransomware attack
BleepingComputer
LockBit lied: Stolen data is from a bank, not US Federal Reserve
BleepingComputer
July-August Threat Update
Cyber Security Centre Isle of Man
District of New Jersey LockBit case summary and victim statistics
U.S. Department of Justice
Superseding complaint describing LockBit victim incidents
U.S. Department of Justice
LockBit claims attack on Wichita as city struggles with payment issues
Recorded Future News
Foxconn confirms cyberattack claimed by Nitrogen ransomware gang
BleepingComputer
Capital Health attack claimed by LockBit ransomware
BleepingComputer
LockBit claims November attack on New Jersey hospital
Recorded Future News
California union confirms ransomware attack following LockBit claims
Recorded Future News
Boeing confirms cyberattack amid LockBit ransomware claims
BleepingComputer
United States Sanctions Affiliates of Russia-Based LockBit Ransomware Group
U.S. Department of the Treasury
LockBit ransomware exploits Citrix Bleed in attacks
BleepingComputer
Royal Mail cyberattack linked to LockBit ransomware operation
BleepingComputer
TSMC denies LockBit hack as ransomware gang demands $70 million
BleepingComputer
LockBit
Wikipedia
Substitute Notice of Data Breach
Evolve Bank & Trust
Taiwanese semiconductor company hit by ransomware attack
The Record from Recorded Future News
City of Oakland ransomware confirmation
BleepingComputer
Joint Cybersecurity Advisory: Understanding Ransomware Threat Actors: LockBit
CISA and international partners