LockBit is a ransomware-as-a-service (RaaS) operation that emerged in September 2019 as ABCD, rebranded as LockBit 2.0 in 2021 and LockBit 3.0 in 2022, and later resurfaced with LockBit 5.0. The operation supplies affiliates with ransomware payloads, decryption capability, infrastructure, and negotiation support in exchange for a share of ransom payments. LockBit is known for rapid, automated enterprise-wide encryption and double extortion: affiliates exfiltrate data before encrypting systems and threaten public release. Some affiliate activity has used triple-extortion pressure, including threatened distributed denial-of-service activity and direct contact with victims’ customers or partners.
Observed LockBit affiliate intrusions have involved exploitation of exposed VPN appliances and remote desktop services, password spraying and brute-force attacks, and exploitation of public-facing applications. Post-compromise tradecraft includes credential dumping, Active Directory and network reconnaissance, lateral movement through remote administration protocols and tools, abuse of Group Policy to weaken endpoint protections, persistence through legitimate remote-access software, and data exfiltration using file-transfer utilities. LockBit has targeted organizations of all sizes across healthcare, financial services, manufacturing, education, government, technology, and other critical sectors, with substantial activity affecting organizations in the United States, United Kingdom, Germany, France, and Australia. LockBit ransomware variants have targeted Windows, Linux, and VMware ESXi environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A critical PaperCut remote-code-execution vulnerability, CVE-2023-27350, was chained with CVE-2023-27351 in April 2023 attacks linked to the LockBit and Clop ransomware gangs. Bl00dy Ransomware later exploited CVE-2023-27350 for initial access. | A critical remote code execution vulnerability (CVE-2023-27350) and a high-severity information disclosure flaw (CVE-2023-27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs.
CVE-2023-27351, a high-severity information-disclosure flaw, was chained with CVE-2023-27350 during April 2023 attacks linked to LockBit and Clop. | A critical remote code execution vulnerability (CVE-2023-27350) and a high-severity information disclosure flaw (CVE-2023-27351) were chained in April 2023 attacks linked to the LockBit and Clop ransomware gangs.
Warlock and other groups exploited newly discovered vulnerabilities in internet-exposed, unpatched on-premises Microsoft SharePoint servers. The report identifies the SharePoint ToolShell vulnerability as central to the campaign.
Warlock appears to be a customized derivative of the leaked LockBit 3.0 builder. In mid-2025, threat actor Storm2603 deployed both LockBit Black and Warlock in the same attack chains against SharePoint environments.
事例2:Citrix製VPN機器「NetScaler」の情報漏れ(2023年/Citrix Bleed) この事例は、実はスコアの付け方そのものが割れた、象徴的な一件です。 同じ脆弱性なのに、NVD(米国国立脆弱性データベース)は7.5(HIGH)、ベンダーであるCitrix自身は9.4(CRITICAL)と評価しました。 中身は「メモリの内容が少し漏れる」という一見地味なものでした。 ところが漏れる内容にログインセッションの情報が含まれていたため、攻撃者はIDやパスワード、多要素認証(二段階認証)すら突破して、正規利用者になりすますことができました。 被害を受けた航空機大手Boeing社が自ら情報を提供し、CISAなどの共同勧告により、LockBit(ロックビット)がこの脆弱性を悪用したことが明らかとなっています | CISAなどの共同勧告により、LockBit(ロックビット) がこの脆弱性を悪用したことが明らかとなっています。
The security researcher noted that all the Pulse Secure VPN servers included in the list were running a firmware version vulnerable to the CVE-2019-11510 vulnerability. Bank Security believes that the hacker who compiled this list scanned the entire internet IPv4 address space for Pulse Secure VPN servers, used an exploit for the CVE-2019-11510 vulnerability to gain access to systems, dump server details (including usernames and passwords), and then collected all the information in one central repository.
The agency particularly warns companies to patch their Fortinet networking devices for CVE-2018-13379, a vulnerability that has been identified as the entry point for many LockBit 2.0 attacks. | Australia's cybersecurity agency has issued a security advisory on Friday warning about a sudden spike in LockBit ransomware attacks across the country... The ACSC has observed LockBit affiliates successfully deploying ransomware on corporate systems in a variety of sectors including professional services, construction, manufacturing, retail and food.
The ActiveMQ episode was compiled from reporting on exploitation of CVE-2023–46604 against an exposed server. The chain continued through discovery, remote access activity, and LockBit deployment...
Log4Shell (CVE-2021-44228) Disclosed on December 9th, 2021, Log4Shell (CVE-2021-44228) is one of the more memorable recent supply chain vulnerabilities with widespread industry impact. This was a critical remote code execution vulnerability in Apache Log4J, a Java logging library utility used by many applications.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. | This is seen with CVE-2024–55591, which was also incorporated by LockBit and SuperBlack ransomware operations.
LockBit 3.0 affiliates are exploiting CVE-2023–4966, known as Citrix Bleed, in Citrix Netscaler web app delivery control (ADC) and Gateway appliances.
In July 2022, Dark Lab security firm reported the abuse of YDArk within a SonicWall SMA100 exploitation campaign aimed to leverage CVE-2019–7481 and CVE-2021–20028 on internet-exposed appliances to install Lockbit ransomware.
In July 2022, Dark Lab security firm reported the abuse of YDArk within a SonicWall SMA100 exploitation campaign aimed to leverage CVE-2019–7481 and CVE-2021–20028 on internet-exposed appliances to install Lockbit ransomware.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
Starting in mid-July 2025, threat actors began actively exploiting two path traversal vulnerabilities affecting on-premises SharePoint servers: CVE-2025-53770 and CVE-2025-53771. These two vulnerabilities are related to CVE-2025-49704 and CVE-2025-49706... attackers managed to eliminate the need to be authenticated to obtain a valid signature, resulting in unauthenticated remote code execution.
Initial Access and Persistence CVE-2024-55591 and CVE-2025-24472 allow unauthenticated attackers to gain super_admin privileges on vulnerable FortiOS devices (<7.0.16) with exposed management interfaces... Another common exploitation method we observed involved the threat actor using the fortigate-firewall account to exploit CVE-2025-24472 rather than CVE-2024-55591.
The experts argued that the attackers likely did not exploit recently disclosed CVE-2022-41040 and CVE-2022-41082 vulnerabilities. | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.
The experts argued that the attackers likely did not exploit recently disclosed CVE-2022-41040 and CVE-2022-41082 vulnerabilities. | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.
Looking at the Microsoft Exchange Server vulnerability history, the remote code execution vulnerability was disclosed on December 16, 2021 (CVE-2022-21969) | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.
According to malware research group vx-underground citing LockBitSupp, the alleged leader of the LockBit operation, law enforcement hacked into the ransomware operation’s servers using a known vulnerability in the popular web coding language PHP. The vulnerability used to compromise its servers is tracked as CVE-2023-3824, a remote execution flaw patched in August 2023, giving LockBit months to fix the bug. | A sweeping law enforcement operation led by the U.K.’s National Crime Agency (NCA) this week took down LockBit, the notorious Russia-linked ransomware gang... It has long been known that LockBit, which first entered the competitive cybercrime scene in 2019, is one of, if not the most prolific ransomware gangs.
Researchers at Huntress Security Operations Center (SOC) observed what they call "a sharp uptick" in exploitation activity targeting Bomgar Remote Support (now part of BeyondTrust), with attackers reaching systems through a critical unauthenticated remote code execution (RCE) flaw, CVE-2026-1731.
44 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Uit onderzoek bleek dat de LockBit 3.0 groep achter de hack zit. Alle servers, back-ups en data waren versleuteld met ransomware.
In 2023, a critical flaw in PaperCut MF and NG (CVE-2023-27350, CVSS score: 9.8) was exploited by Russian threat actors as well as a financially motivated hacking group called Lace Tempest to deliver Cl0p and LockBit ransomware.
Warlock appears to be a customized derivative of the leaked LockBit 3.0 builder. In mid-2025, threat actor Storm2603 deployed both LockBit Black and Warlock in the same attack chains against SharePoint environments.
Warlock previously deployed LockBit-derived ransomware with the .x2anylock extension.
Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky.
例えば「 LockBit 」は 7 月、 8 月とリークサイト掲載数にして全体の 30 %以上を占めていましたが、今月は 14.4% とその割合を落としています。
27 distinct techniques documented for this family, organized by ATT&CK tactic.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
Hackers are actively exploiting a vulnerability in all versions of PaperCut NG and PaperCut MF in zero-day attacks; Internet-exposed PaperCut Application Server web interfaces are specifically at risk. Historical exploitation of CVE-2023-27350 allowed unauthenticated attackers to bypass authentication and remotely execute code on vulnerable servers.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
This report further identified spear phishing as the initial access technique employed during the incident that yielded the analyzed malware sample. Similarly, in December 2022, research observed LockBit spreading through malicious documents (maldocs), which attackers often distribute through phishing.
The command-line interface mirrors the Windows version's formatting and functionality, providing attackers with the same operational flexibility across both platforms.
attackers leveraged it to run a PowerShell script that allows them to download and execute a file containing malicious payload
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
Trend Research analysis found that the Windows binary uses heavy obfuscation and packing
it terminates security-related services by comparing hashed service names against a hardcoded list of 63 values, then clears all event logs using the EvtClearLog API after encryption completion.
-w Encryption mode: all: Encrupt all files local: Encrypt local files net: Encrypt network files Enable wipe free space after encryption
More recently, in March 2023, the Cybersecurity and Infrastructure Security Agency (CISA) issued a #StopRansomware alert about the group in which it identified remote desktop protocol (RDP) compromise, drive-by compromise, phishing, abuse of valid accounts, and exploitation of public-facing applications as initial access techniques observed in LockBit attacks.
“[Ze] maken zijwaartse bewegingen in het netwerk (lateral movement) om van de ene computer naar de andere te springen.”
U.S. Bancorp said recent claims of data theft by a ransomware gang are related to a breach involving a contractor for a third-party... traced it back to “a potential cyber incident…related to a fourth party event that occurred outside” of their environment.
LockBit added US Bank to its data leak site late Wednesday and gave the organization 14 days to meet its ransom demand. The group did not provide details about the number of files it claims to possess or the type of information that may have been stolen.
LockBit listed US Bank on its leak site late Wednesday night, giving the bank 14 days to meet its ransom demand before threatening to release the stolen files.
Seventeen transfers larger than 10 MB, representing an exchange of approximately 11.71 GB, occurred between May 1 and May 6... eight of those nine IP addresses, all of which belong to a U.S. cloud service provider... could serve as proxies for other malicious activity, like data exfiltration.
Ransomware threats “aim[] to lock down critical data and disrupt operations for financial gain”; LockBit is noted for “speed and efficiency in encrypting systems.”
1,227 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation that used ransom notes and infected-machine wallpapers to recruit insiders able to provide VPN, remote desktop, and email credentials.
Ransomware family mentioned as historically linked to exploitation of PaperCut vulnerabilities in April 2023.
Ransomware operation mentioned as a historical user of the prior PaperCut authentication-bypass-to-RCE chain.
Ransomware delivered through exploitation of the 2023 PaperCut vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.