LockBit is a financially motivated ransomware operation known for its LockBit 2.0 and LockBit 3.0 activity, as well as LockBit Black and later LockBit 5.0 branding. The operation has conducted ransomware and extortion attacks against organizations across multiple sectors, including manufacturing, financial services, health care, and professional services. LockBit attacks have encrypted servers, business systems, and backups, caused operational disruption, and in some cases involved suspected theft of personal or other sensitive data. The group uses double-extortion pressure, combining encryption with threats of data disclosure, and has operated a public-facing extortion infrastructure. LockBit 2.0 solicited insiders through ransom notes and victim-system wallpapers, seeking credentials for remote-access and email services. LockBit activity has been linked to exploitation of the PaperCut vulnerabilities CVE-2023-27350 and CVE-2023-27351 for initial access. Reported intrusions have also involved compromise of weakly protected remote-work administrator accounts. LockBit-associated activity has been linked to use of Rclone for data theft. LockBit uses affiliates in its operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
7 CVEs this actor has used in observed campaigns. 7 of them exploited in the wild.
The critical PaperCut remote-code-execution vulnerability CVE-2023-27350 and high-severity information-disclosure flaw CVE-2023-27351 were exploited together in April 2023 attacks linked to LockBit and Clop. Bl00dy later used CVE-2023-27350 for initial access.
CVE-2023-27351 is a high-severity information-disclosure vulnerability that was exploited together with CVE-2023-27350 in April 2023 PaperCut attacks linked to LockBit, Clop, MuddyWater, and APT35.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
Beginning on March 24th, 2024, eSentire observed a significant increase in exploitation of CVE-2023-48788 (CVSS: 9.8). CVE-2023-48788 is a SQL injection flaw in FortiClientEMS software. Exploitation would allow an unauthenticated remote threat actor to execute code or commands through specially crafted requests, enabling initial access into organizations.
2 more CVEs tied to this actor tracked in Mallory.
739 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used ransom notes and compromised-host wallpapers to recruit insiders who could provide VPN, remote desktop, and email credentials.
Recorded six ransomware claims and newly appeared in the weekly top-ten activity ranking.
Historically linked to ransomware attacks exploiting PaperCut vulnerabilities.
Previously linked to April 2023 attacks chaining PaperCut vulnerabilities CVE-2023-27350 and CVE-2023-27351.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.