LockBit is a prominent ransomware family and ransomware-as-a-service operation that became one of the most prolific extortion threats globally. Multiple major versions have circulated, including LockBit 2.0, LockBit 3.0, and LockBit Black, with activity spanning enterprise environments across many sectors and regions. The operation is associated with large-scale data theft and double-extortion tactics in which victim data is exfiltrated before encryption and later used to pressure organizations into paying ransom.
LockBit intrusions have been linked to common ransomware tradecraft including credential theft, lateral movement, and post-compromise deployment across Windows networks. Reported operator and affiliate behavior includes use of legitimate remote administration and execution utilities such as PsExec for lateral movement, NirSoft credential-recovery tools and Mimikatz for credential access, and remote-access software during hands-on-keyboard operations. LockBit activity has also been associated with exploitation of public-facing systems and with post-compromise use of web shells in attacks against poorly managed Windows web servers. In at least one reported case involving a Windows web server intrusion, a threat actor believed to be UAT-8099 uploaded a web shell and later deployed LockBit 3.0 alongside additional remote-control and proxy tooling.
The malware has repeatedly been tied to high-impact enterprise incidents, including attacks involving substantial data exfiltration and multimillion-dollar ransom demands. LockBit has targeted organizations in diverse industries and has remained influential enough that shared affiliates and overlapping tradecraft have been discussed alongside other major ransomware groups. It is widely regarded as one of the defining ransomware threats of the early-to-mid 2020s.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
24 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Log4Shell (CVE-2021-44228) Disclosed on December 9th, 2021, Log4Shell (CVE-2021-44228) is one of the more memorable recent supply chain vulnerabilities with widespread industry impact. This was a critical remote code execution vulnerability in Apache Log4J, a Java logging library utility used by many applications.
CVE-2024–21762 and CVE-2024–55591: Critical vulnerabilities in Fortinet’s FortiGate and FortiProxy devices, enabling authentication bypass and remote code execution. | This is seen with CVE-2024–55591, which was also incorporated by LockBit and SuperBlack ransomware operations.
I conducted a retrospective study on the vulnerability CVE-2023-4966, commonly known as Citrix Bleed, which allows attackers to easily bypass authentication in Citrix's Citrix ADC and Citrix Gateway products, over the course of six months. Initially exploited by some attackers as a zero-day in August 2023, a patch was released on October 10, followed by the publication of a PoC in late October, after which various attackers exploited the vulnerability.
LockBit 3.0 affiliates are exploiting CVE-2023–4966, known as Citrix Bleed, in Citrix Netscaler web app delivery control (ADC) and Gateway appliances.
In July 2022, Dark Lab security firm reported the abuse of YDArk within a SonicWall SMA100 exploitation campaign aimed to leverage CVE-2019–7481 and CVE-2021–20028 on internet-exposed appliances to install Lockbit ransomware.
In July 2022, Dark Lab security firm reported the abuse of YDArk within a SonicWall SMA100 exploitation campaign aimed to leverage CVE-2019–7481 and CVE-2021–20028 on internet-exposed appliances to install Lockbit ransomware.
Starting in mid-July 2025, threat actors began actively exploiting two path traversal vulnerabilities affecting on-premises SharePoint servers: CVE-2025-53770 and CVE-2025-53771. These two vulnerabilities are related to CVE-2025-49704 and CVE-2025-49706... attackers managed to eliminate the need to be authenticated to obtain a valid signature, resulting in unauthenticated remote code execution.
The version of Velociraptor observed in this incident was outdated (version 0.73.4.0) and exposed to a privilege escalation vulnerability (CVE-2025-6264), which may have been leveraged for persistence as this vulnerability can lead to arbitrary command execution and endpoint takeover.
Starting in mid-July 2025, threat actors began actively exploiting two path traversal vulnerabilities affecting on-premises SharePoint servers: CVE-2025-53770 and CVE-2025-53771. These two vulnerabilities are related to CVE-2025-49704 and CVE-2025-49706... attackers managed to eliminate the need to be authenticated to obtain a valid signature, resulting in unauthenticated remote code execution.
CVE-2018-13379 : A path traversal vulnerability in Fortinet SSL VPNs that was routinely exploited by multiple threat actors, including the LockBit ransomware group, across several years.
PaperCut servers have been previously breached by ransomware gangs in 2023 by exploiting a critical, unauthenticated remote code execution (RCE) vulnerability (CVE–2023–27350)... One month later, CISA and the FBI issued a joint advisory warning that the Bl00dy Ransomware gang had also begun exploiting the CVE-2023–27350 RCE vulnerability to gain initial access to the networks of educational organizations.
PaperCut servers have been previously breached by ransomware gangs in 2023 by exploiting a critical, unauthenticated remote code execution (RCE) vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351).
Initial Access and Persistence CVE-2024-55591 and CVE-2025-24472 allow unauthenticated attackers to gain super_admin privileges on vulnerable FortiOS devices (<7.0.16) with exposed management interfaces... Another common exploitation method we observed involved the threat actor using the fortigate-firewall account to exploit CVE-2025-24472 rather than CVE-2024-55591.
The experts argued that the attackers likely did not exploit recently disclosed CVE-2022-41040 and CVE-2022-41082 vulnerabilities. | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.
The experts argued that the attackers likely did not exploit recently disclosed CVE-2022-41040 and CVE-2022-41082 vulnerabilities. | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.
Looking at the Microsoft Exchange Server vulnerability history, the remote code execution vulnerability was disclosed on December 16, 2021 (CVE-2022-21969) | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.
According to malware research group vx-underground citing LockBitSupp, the alleged leader of the LockBit operation, law enforcement hacked into the ransomware operation’s servers using a known vulnerability in the popular web coding language PHP. The vulnerability used to compromise its servers is tracked as CVE-2023-3824, a remote execution flaw patched in August 2023, giving LockBit months to fix the bug. | A sweeping law enforcement operation led by the U.K.’s National Crime Agency (NCA) this week took down LockBit, the notorious Russia-linked ransomware gang... It has long been known that LockBit, which first entered the competitive cybercrime scene in 2019, is one of, if not the most prolific ransomware gangs.
Researchers at Huntress Security Operations Center (SOC) observed what they call "a sharp uptick" in exploitation activity targeting Bomgar Remote Support (now part of BeyondTrust), with attackers reaching systems through a critical unauthenticated remote code execution (RCE) flaw, CVE-2026-1731.
Storm-2603... observed stealing MachineKeys and deploying Warlock and Lockbit ransomware... They conduct lateral movement using PsExec and Impacket, deploying Warlock and LockBit ransomware to encrypt systems. | Exploited vulnerabilities include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, collectively known as ToolShell. CVE-2025-49704: A remote code execution vulnerability allowing attackers to run arbitrary code without authentication.
Storm-2603... observed stealing MachineKeys and deploying Warlock and Lockbit ransomware... They conduct lateral movement using PsExec and Impacket, deploying Warlock and LockBit ransomware to encrypt systems. | CVE-2025-49706: A spoofing vulnerability enabling post-authentication remote code execution on affected SharePoint servers.
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
Affiliates of LockBit ransomware have previously targeted vulnerabilities in ConnectWise ScreenConnect (i.e., CVE-2024-1708 and CVE-2024-1709) for initial access.
...threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges.
Affiliates of LockBit ransomware have previously targeted vulnerabilities in ConnectWise ScreenConnect (i.e., CVE-2024-1708 and CVE-2024-1709) for initial access.
37 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In a real-world case, evidence was found that the threat actor, believed to be UAT-8099, used LockBit 3.0 Ransomware; after uploading a web shell, they attempted to gain control and manipulate SEO using Potato, AnyDesk, GotoHTTP, LCX, the NPS client (npc.Exe), BadIIS...
The LockBit ransomware group, active since around 2019... In December 2024, the group announced its newest ransomware version, “Lockbit 4”. Lockbit 4 has two versions, Black and Green, In this article we will analyze the green version.
LockBit 3.0 affiliates are exploiting CVE-2023–4966, known as Citrix Bleed, in Citrix Netscaler web app delivery control (ADC) and Gateway appliances.
We investigated a recent LockBit extortion incident that occurred in Q3 2023... In September 2019, Cybereason found this hostname in old LockBit 2.0 extortions...
CYBLE identified the DragonForce ransomware binary as being based on LockBit 3.0 (Black) ransomware.
The attackers used a version of the popular LockBit 3.0 ransomware, compiled from publicly available source code, to encrypt the data.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The MSI file has 4 embedded objects within it... 7zip, and at last the encrypted archive... The script.bat contains commands to extract the infected file from the archive and execute it
We are using MSI abuse for this evasion technique. The most common format for installing any application designed for Windows is either “EXE” or “MSI.”
In December 2024, LockBit’s Leak site noted the release of LockBit 4.0, and the S2W Threat Intelligence Center analyzed the updated LockBit Green, identifying the addition of self-deletion and the ability to delete event logs.
Each family drops a note of a recognizable size, which serves as a fingerprint.
selection_domain_http: url.domain|endswith: - 'karma0.xyz' - 'random-strings.xyz' - 'decrypt-support.xyz' - 'supportpanel.xyz' - 'data-leaks.xyz' ... selection_url_paths: url.path|contains: - '/gate.php' - '/index.php?id='
selection_url_paths: url.path|contains: - '/gate.php' - '/index.php?id=' ... selection_hash_md5: hash.md5: - e818a9afd55693d556a47002a7b7ef31 # -- Hash IOC’leri (Smokeloader MD5)
hollandbulbfarms.com — a company operating in the US — has fallen victim to a ransomware attack conducted by the group lockbit5.
774 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware group/family mentioned for comparison to the complexity of the investigation.
A ransomware operation mentioned as having used Media Land LLC hosting services.
Lockbit6
A ransomware group noted here for a sharp increase in prevalence during June 2026.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.