← All actors

LockBit

Aliases: LockBit 3.0, LockBit Black

Source profile review date: 2026-05-31

Added to the source registry: 2020-10-21 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

Locally generated translation; linguistic review is still pending.

Executive summary

LockBit is an industrialized ransomware-as-a-service ecosystem with large affiliate variation, broad victim base and strong publication pressure.

LockBit should be treated as an ecosystem file. The brand name is visible, but the technical attack chain differs per affiliate; therefore research should reconstruct evidence by phase.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    LockBit is one of the best known ransomware-as-a-service ecosystems of recent years. CISA and international partners describe LockBit as a common ransomware variant with attacks against organizations of different sizes and sectors, including critical infrastructure. The main feature is scale: operators, affiliates, leak site, negotiation process and tooling together form a criminal business model.

    For management, a LockBit claim means that three risk derivatives must be examined simultaneously: operational disruption, data diode and reputation or chain pressure. The technical route may vary. Some affiliates use stolen credentials or remote access, other vulnerable internet-facing systems, initial access brokers or known tooling. Therefore, a LockBit profile should never be reduced to one list of hashes.

    The value of this file is the forensic framework. Each LockBit entry must determine how the actor entered, what privileges were used, what data was accessed, which systems have been encrypted, or where recovery means have been hit and what publication pressure exists.

    Grouping and development

    LockBit developed into a RaaS franchise in which many affiliates could operate under the same brand name. CISA stresses that LockBit attacks due to the number of unrelated affiliates can vary significantly in TTPs. This is essential: the name LockBit is a starting point, not a final conclusion.

    The group used leak-site publication, bargaining pressure and reputation as leverage. Even after infrastructure disruption, LockBit remains analytically relevant because affiliates, techniques and access routes can flow to other ecosystems. For CTI therefore, LockBit should be considered a blueprint for industrialised ransomware.

    For organisations LockBit helps to test customer integrity. The question is not only whether one can detect LockBit, but whether the organisation can withstand affiliate behavior: access via valid accounts, privilege building, fast lateral movement, data diary and repair disruption.

    Operation and attack chain

    Research starts at earliest know access. Collect VPN-, RDP-, firewall-, proxy-, identity-, SSO- and EDR-logs. Search for stolen credentials, brute force, MFA-omsailing, exposed services, vulnerable applications and broker access. As affiliates differ, the first hypothesis must remain broad.

    In the middle phase, discovery, credential access and lateral movement are decisive. Relevant artifacts include domain enumeration, admin group changes, LSASS access, credential dumping, PowerShell, WMI, PsExec-like behaviour, RDP- jumps, remote service creation, GPO- abuse and access to domain controllers or management servers.

    Data dialog and encryption need to be separated. Search for archiving tools, staging directories, Rclone or cloud sync configurations, large file entries, outgoing data traffic, shadow copy actions, service stops, backup server access and ransomware deployment. A LockBit incident without visible encryption may still be a serious data breach.

    Create a timeline by incident that links technical events to publication pressure. When did the claim appear, when did access start, when was data moved and when did encryption take place? Difference between those times helps with source validation and communication.

    Attack pattern from public cases

    LockBit is not a single-shaped attack but a RaaS ecosystem. CISA describes that TTPs may vary per affiliate. In practice, this means that the group can enter via stolen credentials, remote access, vulnerable edge systems or broker access.

    After access, the pattern often revolves around fast privilege escalation, domain exploration, credential access, lateral motion, datastaging and encryption. LockBit affiliates search systems with many data and systems that determine recovery: file servers, domain controllers, backup servers and hypervisors.

    The defense should therefore not look for one LockBit signature, but for the ransomware chain: unusual remote login, admin rights, remote execution, large file entries, archiving, exfiltration and shadow copy or backup actions.

    LockBit victims come from many sectors. The lesson is that exposure and identity hygiene are more important than sector. An organization with weak remote access and poorly separated backups is attractive, regardless of industry.

    Known IOCs and artifacts

    CISA AA23-075A and AA23-165A contain LockBit 3.0 and LockBit-ecosystem information. The usable artifacts are not only hashes, but also behavior: discovery, credential access, exfiltration and encryption.

    Known LockBit studies often mention ransom notes, modified file extensions, remote execution tools, archiving and exfiltration. These artifacts should always be linked to the relevant affiliatecase.

    For defense, there are specific search points: new scheduled tasks of services, PsExec-like behaviour,PowerShell /WMI , largeSMB- lectures,Rclone -like uploads, removal of shadow copies and unexpected access to backup servers.

    Since LockBit affiliates can switch strongly, IOC advisors should be used as a starting point for retro-hunting. Structural detection should remain on behaviour.

    Victims and historical context

    LockBit is publicly linked to a wide range of sectors such as production, government, care, education, logistics, financial services, IT- services and food/agri. Due to this width, sector alone is not a sufficient predictor. More relevant are exposure, identity hygiene, data volume and recovery dependence.

    Save per victim claim: victim name, sector, country, date of claim, source, publication status, data types, indication of encryption and relationship to supplier chains. Supplier impact is often as important as direct impact for organisations.

    Detection and follow-up

    Priorities: phishing-resistant MFA, cutting of remote access, patching of edge systems, least privilege, PAM, EDR-hardening, application control, central logging, segmentation, exfiltration monitoring and immutable/offline backups. Test recovery without confidence in the primary domain.

    In a LockBit-hit, the triage should not stick in the brand name. Valde source, determine sector and customer relationship, check access routes, turn Hunts on affiliate behavior and document uncertainties. LockBit is an ecosystem; the incident evidence determines the conclusion.

    Deep forensic file

    LockBit research should take affiliate variation as the starting point. It is tempting to explain an incident from the brand name, but just in LockBit the technical route can vary considerably. Therefore, the researcher must build up proof as if the group name is still unknown: first access, privilege use, data access, tooling, exfiltration, encryption and publication. Only then will the claim be linked to the LockBit-ecosystem.

    Initial access deserves wide scope. Check credential stuffing, VPN, RDP, Citrix, vulnerable edge equipment, phishing, abuse of vendor accounts and initial access brokers. Also look at old accounts that re-enable and accounts without modern MFA. LockBit affiliates search usable access; the defense question is what access was seen internally as normal but was exploitable externally.

    Privilege escalation and lateral movement must be worked out by account and host. Which accounts did domain controllers reach, which hosts served as springboard, which management protocols were used and which GPO or remote execution methods came back? A LockBit incident can quickly become domain-wide when admin rights are widely reused. This needs to be made concrete in the report.

    Data dialog should be described separately from encryption. Search for staggering, compression, Rclone-like behaviour, cloud uploads and large file entries. Determine which data was found interesting by the actor and which data categories are administratively sensitive. A LockBit claim without proven exfiltration requires communication other than a claim with concrete data samples.

    Recoverability is a separate forensic layer. Check backup servers, hypervisors, storage management, EDR-management and privileged access. If the actor has explored or modified these systems, recovery must be treated as potentially compromised. Recovery from backup without root-cause analysis can give the actor re-access.

    For detection engineering LockBit is usable as generic ransomware affiliate scenario. Build use cases around anomalous remote access, privilege changes, credential dumping, remote execution, EDR tampering, data staging, exfiltration and mass encryption. Each use case must have a log source, owner, response action and false positive expectation. Thus, the profile becomes operational instead of descriptive.

    What to look for

    LockBit is an ecosystem with affiliates. This may lead to different access per incident. Note the behavior instead of just the brand name: remote access, valid accounts, privilege escalation, lateral movement, datataging, exfiltration, EDR-tamping and encryption preparation.

    Important signals include suspicious VPN or RDP-logins, new admin rights, credential dumping, PowerShell, WMI, PsExec-like behavior, remote service creation, large file entries, archiving, cloud uploads, shadow copy actions and backup server access. A LockBit claim asks for research into the entire chain.

    Because affiliates differ, an old IOC- list is never enough. An organization should be able to see if the attack phases take place even when the used binary or infrastructure changes. Behavioral detection is more important than hashes alone.

    How to arm yourself against LockBit

    Decrease the likelihood of affiliate access. Limit exposed remote access, force MFA, patch edge systems, close old accounts, limit vendor accounts and monitor logins from unknown locations. Many ransomware starts with access that already existed but was not adequately monitored.

    Protect privilege and lateral movement. Use least privilege, separate admin accounts, PAM where possible, segmentation between workstations and servers, and detection on remote execution. An affiliate that cannot scale up can make much less impact.

    Make data diode stand visible. Monitor mass file access, compression, staging directories, cloud sync and outbound volume. LockBit uses publication printing; knowing which data has been moved or not is crucial to communication and decision making.

    Victim pattern and lessons

    LockBit has been publicly visible in a wide range of sectors, including production, government, care, logistics, education, financial services and IT. The lesson is that sector is less decisive than exposure, identity hygiene, data volume and recovery dependence.

    The affiliate model can make a LockBit incident technically very different from an incident at another organisation. Visitors should therefore not look for one LockBit signature, but for reusable attack phases.

    A claim with a supplier can be as relevant as a direct claim. Therefore, check suppliers' relationships, shared data, remote management channels and contractual reporting obligations when LockBit appears in your chain.

    A direct defense check is to check if an attacker with one VPN- account can move on to file shares, domain controllers or backup management. If possible, the environment is vulnerable to LockBit-like affiliate behavior.

    See if large data transfers are visible. Many organizations do notice encryption, but miss the hours before archives are created and data is prepared. This stage determines the extortion pressure later.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    artifactLockBit 3.0 ransom note / encrypted-file artefactsCISA AA23-075AUse with incident context; affiliate variation is significant
    behaviorPsExec/WMI/PowerShell remote execution followed by mass file encryptionCISA AA23-075A / AA23-165AObserved ransomware tradecraft pattern
    behaviorlarge archive creation and Rclone-like exfiltration before encryptionCISA LockBit advisoriesData theft phase to hunt before impact
    behaviorshadow copy deletion or backup interferenceCISA LockBit advisoriesRecovery-pressure pattern

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.