LockBit is a Russia-linked, financially motivated ransomware-as-a-service (RaaS) operation. It operates through an affiliate model in which affiliates conduct intrusions and deploy LockBit ransomware, while the core operation provides ransomware tooling and extortion infrastructure. Major variants include LockBit 2.0, LockBit 3.0, also known as LockBit Black, and LockBit 5.0. The operation has targeted large organizations across multiple sectors and countries, including healthcare and industrial organizations. LockBit operations commonly combine rapid file encryption with double extortion: data is stolen before or during the encryption phase and victims are threatened with public disclosure if they do not pay. LockBit has used exploitation of internet-facing vulnerabilities for initial access, including the 2023 PaperCut vulnerability chain involving CVE-2023-27350 and CVE-2023-27351. The group has also solicited insiders for corporate VPN, remote-desktop, and email credentials, reflecting interest in credential-based access to high-value targets. Reported LockBit intrusions have caused significant outages through encryption of production servers and backups, and have involved theft of personal data. The group has been associated with use of cloud-transfer tooling for data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
The critical PaperCut remote-code-execution vulnerability CVE-2023-27350 and high-severity information-disclosure flaw CVE-2023-27351 were exploited together in April 2023 attacks linked to LockBit and Clop. Bl00dy later used CVE-2023-27350 for initial access.
CVE-2023-27351 is a high-severity information-disclosure vulnerability that was exploited together with CVE-2023-27350 in April 2023 PaperCut attacks linked to LockBit, Clop, MuddyWater, and APT35.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
Beginning on March 24th, 2024, eSentire observed a significant increase in exploitation of CVE-2023-48788 (CVSS: 9.8). CVE-2023-48788 is a SQL injection flaw in FortiClientEMS software. Exploitation would allow an unauthenticated remote threat actor to execute code or commands through specially crafted requests, enabling initial access into organizations.
2 more CVEs tied to this actor tracked in Mallory.
739 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used ransom notes and compromised-host wallpapers to recruit insiders who could provide VPN, remote desktop, and email credentials.
Recorded six ransomware claims and newly appeared in the weekly top-ten activity ranking.
Historically linked to ransomware attacks exploiting PaperCut vulnerabilities.
Previously linked to April 2023 attacks chaining PaperCut vulnerabilities CVE-2023-27350 and CVE-2023-27351.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.