Overview

Platforms: Windows · Linux · macOS · ESXi
Variants: LockBit Red · LockBit Black · LockBit Green · LockBit 3.0 · LockBit 2.0
Extensions: .abcd · .lockbit
ATT&CK software: StealBit · Angler · Pikabot
Initial access: Exploit Public-Facing Application · Valid Accounts · External Remote Services
Top countries: US · GB · FR · DE · CA
Observed sectors: Manufacturing · Professional Services · Healthcare · Technology · Financial Services
Tracked victims: 3,231

Attribution

Dmitry Yuryevich Khoroshev (LockBitSupp) VERIFIED
Operator identity
LockBit VERIFIED
Group identity

Affiliates

Mikhail Vasiliev
Russian-Canadian national who pleaded guilty in U.S. federal court to charges related to his role in the LockBit ransomware conspiracy.
Ruslan Astamirov
Russian national charged by the U.S. Department of Justice for his involvement in the LockBit ransomware conspiracy; indictment proceedings active.

Activity

Initial Access

Exploitation of public-facing applications
LockBit affiliates have exploited internet-facing services and vulnerabilities to obtain initial access.
Remote services and valid accounts
LockBit affiliates have used compromised credentials, VPN access and RDP for initial access.
Phishing
Phishing and spearphishing have been documented as initial-access techniques used by LockBit affiliates.

Recent Observations

Continued LockBit 5.0 activity
September 2026
Leak-site activity
LockBit 5.0 continued publishing new victim claims in September 2026.
LockBit 5.0 affiliate rebuilding
March 2026
Operational activity
LockBit 5.0 showed renewed growth in victim postings during Q1 2026 as the operation rebuilt its affiliate ecosystem.
LockBit 5.0 launch
September 2025
Operational change
LockBit 5.0 was launched on underground forums as the next generation of the LockBit RaaS operation.

TTPs

ATT&CK coverage: 9 techniques
T1190 Exploit Public-Facing Application
VERIFIED
Affiliates leverage vulnerabilities in edge devices and public applications such as Citrix, Fortinet, and VPN gateways for initial entry.
T1078 Valid Accounts
VERIFIED
Use of stolen credentials purchased from initial access brokers or captured via phishing to gain access to victim environments.
T1133 External Remote Services
VERIFIED
Deployment of tools to facilitate RDP access or exploitation of existing remote management infrastructure.
Show more TTPs (6)
T1059.003 Windows Command Shell
VERIFIED
Extensive use of command-line interfaces and batch scripts for reconnaissance, lateral movement, and payload execution.
T1484.001 Group Policy Modification
VERIFIED
Modification of Group Policy Objects to push malicious binaries or disable security settings across the domain.
T1003.001 LSASS Memory
VERIFIED
Use of credential dumping tools like Mimikatz or ProcDump to extract credentials from memory.
T1562.001 Impair Defenses: Disable or Modify Tools
VERIFIED
Affiliates frequently attempt to disable or uninstall antivirus and EDR agents before executing the final encryption payload.
T1490 Inhibit System Recovery
VERIFIED
Execution of commands to delete Volume Shadow Copies and clear Windows Event Logs to hinder forensic recovery.
T1486 Data Encrypted for Impact
VERIFIED
Execution of LockBit ransomware binaries (e.g., LockBit 3.0/Black) to encrypt data across Windows, Linux, and ESXi environments.

Victims

Itaguaí Construções Navais (ICN) CLAIMED
August 2026 BR Manufacturing
Manufacturing organization in BR.
Verbandsgemeinde Rhein-Nahe CLAIMED
July 2026 DE Government
Government organization in DE.
Hanover Police Department CLAIMED
June 2026 US Government
Government organization in US.
Grey High School CLAIMED
May 2026 ZA Education
Education organization in ZA.
Graphique de France CLAIMED
March 2025 US Manufacturing
Manufacturing organization in US.
Show more victims (8)
Crystal D CLAIMED
March 2025 US Manufacturing
Manufacturing organization in US.
AC Investment Management, LLC CLAIMED
March 2025 US Financial Services
Financial Services organization in US.
OYO Hotel & Casinos Las Vegas CLAIMED
January 2025 US
Organization in US.
Topackt IT Solutions GmbH CLAIMED
January 2025 DE Technology
Technology organization in DE.
Equinox CLAIMED
May 2024 US Healthcare
Healthcare organization in US.
Evolve Bank & Trust CONFIRMED
May 2024 US Financial Services
Financial Services organization in US.
Saint Anthony Hospital CONFIRMED
December 18, 2023 US Healthcare
Healthcare organization in US.
Taiwan Semiconductor Manufacturing Company CONFIRMED
June 29, 2023 TW Manufacturing
Manufacturing organization in TW.

CVEs

Exploited by LockBit affiliates for initial access to Fortinet FortiOS SSL VPN gateways.
Associated since: 2020
CVE-2023-3519 has been widely exploited against Citrix ADC and Gateway appliances, but the currently attached source does not directly substantiate exploitation by LockBit affiliates.
Citrix Bleed vulnerability identified as being leveraged by LockBit 3.0 affiliates for initial access.
Associated since: November 2023

Infrastructure

LockBit 3.0 leak site
Primary platform for publishing victim data and double-extortion claims under the LockBit 3.0 (Black) branding.
ONLINE
Last checked: May 15, 2024
Affiliate portal
Infrastructure used to manage affiliate registration, target negotiation, and ransomware binary generation.

Timeline

2024-02-20
Operation Cronos
A multi-national law enforcement operation led by the UK NCA and FBI resulted in the seizure of LockBit infrastructure and the compromise of internal administrative panels.
2022-03-01
LockBit 3.0 emergence
LockBit 3.0, often referred to as LockBit Black, was launched, incorporating new obfuscation methods and a bug bounty program.
2021-06-01
LockBit 2.0 release
LockBit transitioned to version 2.0, introducing the StealBit exfiltration tool and an expanded RaaS program.
Show more events (1)
2019-09-01
ABCD ransomware emergence
The ransomware variant initially referred to as ABCD, the predecessor to LockBit, was first identified in the wild.

Sources

LockBit 2.0
MITRE ATT&CK
Framework
LockBit 3.0
MITRE ATT&CK
Framework
The State of Ransomware — Q1 2026
Check Point Research
Vendor research
Show more sources (61)
LockBit 5.0 ransomware operation
Ransomware.live
Tracker
LockBit, Group G0176
MITRE ATT&CK
Framework
Q1 2026 Ransomware Landscape
Check Point Research
July-August Threat Update
Cyber Security Centre Isle of Man
LockBit
Wikipedia