LockBit is a prolific Russian ransomware-as-a-service operation that emerged in 2020 and became one of the most dominant extortion groups globally. It has operated through an affiliate model in which core operators provide ransomware tooling, leak-site infrastructure, and negotiation mechanisms to numerous affiliates. Known aliases and variants include LockBit 2.0, LockBit 3.0, LockBit Black, and the post-Operation Cronos branding LockBit 5.0. Reporting also references LockBit affiliates and related sub-branding tied to specific campaign waves. LockBit has targeted organizations worldwide across both public and private sectors, including government, healthcare, manufacturing, financial services, telecommunications, education, defense-related organizations, and technology companies. Victimology is broad and opportunistic, with repeated activity documented in the United States, the United Kingdom, France, Germany, Italy, Spain, and South Korea, among other countries. The group is best known for double-extortion ransomware operations that combine file encryption with theft of victim data and threats to publish it on a leak site. Law-enforcement disruption and later reporting showed that LockBit retained stolen victim data even after ransom payments in some cases, undermining its claims that payment would result in deletion. LockBit has also maintained public leak-site operations as part of its extortion model. Operationally, LockBit and its affiliates have used common ransomware intrusion patterns including exploitation of public-facing vulnerabilities, phishing and other initial-access methods, abuse of exposed remote services, credential reuse, lateral movement, privilege escalation, persistence, and large-scale data exfiltration. Public reporting specifically links LockBit 3.0 affiliates to exploitation of CVE-2023-4966, and later reporting describes LockBit 5.0 as retaining cross-platform capability against Windows, Linux, and VMware ESXi environments. In February 2024, an international law-enforcement action known as Operation Cronos seized LockBit infrastructure, including elements of its leak-site and control environment, and significantly damaged the group’s credibility and operational tempo. Authorities reported that LockBit had victimized more than 2,500 organizations worldwide and extorted more than $500 million in ransom payments. Despite that disruption, subsequent reporting indicates continued activity and re-emergence under LockBit 5.0 branding in 2026.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
38 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
Two vulnerabilities were fixed in the PaperCut Application Server that allows remote attackers to perform unauthenticated remote code execution and information disclosure: CVE-2023–27350 ... Unauthenticated remote code execution flaw impacting all PaperCut MF or NG versions 8.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... A PoC exploit for the RCE flaw was released... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
CVE-2023–27351 ... Unauthenticated information disclosure flaw impacting all PaperCut MF or NG versions 15.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
...LockBit ransomware group as they exploited a vulnerability known as ‘Citrix Bleed’ (CVE-2023-4966) during their attacks. LockBit leveraged this flaw to hijack authenticated sessions...
1 more CVE tied to this actor tracked in Mallory.
532 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Persistent legacy ransomware group continuing European operations despite takedowns, relying on compartmentalized affiliates, rebranding, redundant infrastructure, and ongoing affiliate recruitment.
Conducting a ransomware attack resulting in a data breach against briggsplc.com, a UK-based manufacturing/engineering equipment company.
Ransomware group discussed as having retained victims’ stolen data despite promises to delete it after payment, undermining trust in ransom-payment outcomes.
A ransomware-as-a-service operation active from 2020 to 2024 that victimized over 2,500 organizations worldwide and extorted more than $500 million in ransom payments. Its infrastructure and affiliate-trust-based business model were disrupted by Operation Cronos.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.