LockBit is a prolific cybercriminal ransomware operation that has operated as a ransomware-as-a-service (RaaS) ecosystem with a core operator team and a broad affiliate network. It is widely tracked under aliases including LockBit, LockBit 2.0, LockBit Black, LockBit 3.0, LockBit Green, LockBitSupp, and more recently LockBit 5.0. The group is financially motivated rather than a nation-state actor, although its infrastructure and support ecosystem have intersected with other criminal service providers and bulletproof hosting operators. LockBit has targeted organizations across a wide range of sectors and geographies, including manufacturing, education, government, healthcare, retail, technology, consulting, hospitality, and other commercial and public-sector entities. The operation is known for high-volume victimization and public extortion through leak-site postings, and it has remained one of the most recognizable ransomware brands even after law-enforcement disruption and sanctions activity. Operationally, LockBit and its affiliates commonly combine data theft with encryption and extortion, though the broader ransomware landscape in which it operates has increasingly included data-only extortion. Reported tradecraft associated with LockBit activity includes abuse of Remote Desktop Protocol for unauthorized access and lateral movement, use of legitimate remote access and administration tools, and use of common dual-use utilities to support reconnaissance, persistence, and exfiltration. LockBit-linked intrusions have also been associated with use of tools such as FileZilla for exfiltration support, AnyDesk for remote access, and network-scanning utilities for internal discovery. The group has been observed relying on legitimate or allowlisted Windows tools and administrative mechanisms, consistent with broader ransomware affiliate tradecraft. LockBit has also been linked to exploitation trends seen across the ransomware ecosystem, including opportunistic use of exposed services and rapid weaponization of newly disclosed vulnerabilities where affiliates or associated actors can obtain access at scale. The operation’s affiliate model has enabled variation in initial access methods and post-compromise behavior across incidents. The group has undergone multiple branding and malware-version changes. LockBit 2.0 represented a major evolution of the original operation, while LockBit Black and LockBit 3.0 are commonly used names for later variants. Reporting in 2026 also references LockBit 5.0 as a continuing or reconstituted LockBit-branded operation. Despite sanctions and takedowns, LockBit retained measurable market presence in 2026 and showed signs of renewed activity after earlier disruption, indicating resilience of the brand and affiliate ecosystem. LockBit has been repeatedly connected to criminal support infrastructure. U.S. and allied authorities have alleged that bulletproof hosting providers such as Media Land and ML.Cloud supplied infrastructure or services used by LockBit alongside other ransomware groups. Such links underscore LockBit’s dependence on the broader cybercrime-as-a-service ecosystem, including hosting, anonymization, payment facilitation, and other enabling services. Overall, LockBit remains one of the most significant and enduring ransomware brands of the past several years: a decentralized extortion enterprise characterized by aggressive affiliate-driven operations, broad sector targeting, frequent use of legitimate administrative tooling, and sustained adaptability in the face of international law-enforcement pressure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
45 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2018-10562 8.9 Dasan GPON Home Routers LockBit, RansomHouse, Crypto24 Link
Based on their 90-day average detection rates, CVE-2019-12780 leads the list... CVE-2019-12780 9.8 Belkin Wemo Smart Plug LockBit, RansomHouse No
Two vulnerabilities were fixed in the PaperCut Application Server that allows remote attackers to perform unauthenticated remote code execution and information disclosure: CVE-2023–27350 ... Unauthenticated remote code execution flaw impacting all PaperCut MF or NG versions 8.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... A PoC exploit for the RCE flaw was released... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
CVE-2023–27351 ... Unauthenticated information disclosure flaw impacting all PaperCut MF or NG versions 15.0 or later... PaperCut disclosed that these flaws were actively exploited in the wild... Microsoft ... attributed the recent PaperCut attacks to the Clop and LockBit ransomware operations.
...LockBit ransomware group as they exploited a vulnerability known as ‘Citrix Bleed’ (CVE-2023-4966) during their attacks. LockBit leveraged this flaw to hijack authenticated sessions...
1 more CVE tied to this actor tracked in Mallory.
532 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group retaining measurable market share despite sanctions pressure.
Referenced only as background comparison to the complexity of the investigation.
Named as one of the ransomware groups that exploited Log4Shell in incident response cases.
Named as one of the ransomware operations that received attack infrastructure and technical support from the bulletproof hosting providers Media Land and ML.Cloud.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.