Skip to main content
Mallory
MalwareRansomwareUsed by 29 actorsExploits 21 CVEs

LockBit

Also known asLockBit 2.0LockBit 3.0LockBit 5.0LockBit Blacklockbit_ransomware

LockBit is a ransomware and ransomware-as-a-service (RaaS) operation active since at least September 2019, with the ransomware variant first appearing around January 2020. It has operated multiple major versions including LockBit 2.0, LockBit 3.0/LockBit Black, and LockBit 5.0. The operation has been described by U.S. authorities as at times the most active and destructive ransomware group in the world. Reported victim counts range from more than 1,400 attacks worldwide to more than 2,500 victims across at least 120 countries, including about 1,800 in the United States. Victims have included individuals, small businesses, multinational corporations, hospitals, schools, nonprofit organizations, critical infrastructure, and government and law-enforcement agencies.

LockBit operates through affiliates. According to U.S. indictments and complaints, the scheme was created, developed, and administered by Dmitry Yuryevich Khoroshev, aka LockBitSupp, who allegedly ran the service as a RaaS platform, maintained the control panel and leak site, recruited affiliates, and typically took a 20% share of ransom payments. Other charged or identified participants include affiliates Ruslan Magomedovich Astamirov and Mikhail Vasiliev, and developer Rostislav Panev. GOLD MYSTIC is described as operating the LockBit name-and-shame RaaS scheme since mid-2019. LockBit has also been linked in reporting to affiliates such as Wazawaka/Mikhail Matveev, and Mandiant reported that Evil Corp shifted to using LockBit RaaS in some operations.

The malware is used for double extortion: affiliates gain unauthorized access to victim networks, steal data, encrypt stored data, and threaten to publish stolen information on LockBit-controlled leak infrastructure if payment is not made. Supporting content states that LockBit affiliates unlawfully accessed vulnerable systems, stole data, and encrypted victim environments; one incident involved compromise of an Exchange server via web shell, escalation to Active Directory admin within seven days, theft of roughly 1.3 TB of data, and subsequent deployment of LockBit 3.0. Cisco Talos notes that LockBit uses the custom exfiltration tool StealBit. Court documents in the Panev case state that LockBit builder source code, StealBit source code, and control-panel credentials were recovered, and that the builder allowed affiliates to generate custom builds for particular victims.

Capabilities directly mentioned in the content include disabling firewall rules and anti-malware and monitoring software, including Windows Defender, in LockBit 2.0; Base64-encoding of C2 communication in LockBit 3.0; code to disable antivirus tools; code to spread malware across victim networks; and code to print ransom notes to all printers connected to a victim network. LockBit affiliates and related actors have also been observed using standard ransomware tradecraft such as lateral movement with stolen credentials and double-extortion tactics. Talos further notes that LockBit actors have used StealBit for exfiltration and that LockBit, BlackBasta, and Rhysida have encrypted data and defaced victim systems to maximize impact.

The operation has repeatedly targeted high-impact sectors. Mentioned incidents include attacks against hospitals such as Hôpital de Cannes - Simone Veil in France, where LockBit 3.0 caused severe operational disruption, forced computers offline, and led to rescheduling of non-emergency procedures; attacks against Foxconn-related entities; and broad targeting of healthcare, education, manufacturing, and other sectors. The content also notes that LockBit operators expressly prohibit affiliates from targeting Russia and other CIS countries.

Financial impact attributed to LockBit is substantial. U.S. government reporting cited in the content states that LockBit issued over $100 million in ransom demands and received at least tens of millions of dollars in bitcoin in one account, while later DOJ reporting states the group extracted at least approximately $500 million in ransom payments and caused billions of dollars in additional losses. A U.S. Department of State reward notice states that since January 2020 LockBit executed more than 2,000 attacks and received at least $144 million in bitcoin ransom payments.

LockBit was the subject of major international law-enforcement action in February 2024 under Operation Cronos, led by the U.K. National Crime Agency with DOJ, FBI, and international partners. Authorities seized public-facing websites and servers, obtained decryption keys, developed free decryptors for victims, and stated that the disruption significantly diminished LockBit’s reputation and operational capability. Despite this, the content states that LockBit restarted operations about a week later, stood up new leak sites, used updated encryptors and ransom notes, and remained active through 2024. Reporting also notes a May 2025 compromise of the LockBit affiliate control panel, with an SQL database leak containing affiliate/admin records, plaintext passwords, victim profiles, ransom negotiation chats, custom builds, and tens of thousands of bitcoin addresses.

High-confidence indicators and artifacts mentioned in the content include the StealBit exfiltration tool; LockBit builder and control panel; dark web leak/data extortion sites; custom ransomware builds; ransom negotiation chats; and the defacement message used during the 2025 panel compromise: "Don’t do crime CRIME is BAD xoxo from Prague."

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

21 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

21 CVES
CVE-2023-27350Unauthenticated Authentication Bypass and RCE in PaperCut MF/NGExploited in the wild

PaperCut servers have been previously breached by ransomware gangs in 2023 by exploiting a critical, unauthenticated remote code execution (RCE) vulnerability (CVE–2023–27350)... One month later, CISA and the FBI issued a joint advisory warning that the Bl00dy Ransomware gang had also begun exploiting the CVE-2023–27350 RCE vulnerability to gain initial access to the networks of educational organizations.

via bleeping computerbleepingcomputer.com
CVE-2023-27351Authentication Bypass in PaperCut NG/MF SecurityRequestFilterExploited in the wild

PaperCut servers have been previously breached by ransomware gangs in 2023 by exploiting a critical, unauthenticated remote code execution (RCE) vulnerability (CVE–2023–27350) and a high-severity information disclosure flaw (CVE–2023–27351).

via bleeping computerbleepingcomputer.com
CVE-2025-24472FortiOS/FortiProxy Security Fabric authentication bypass via crafted CSF proxy requestsExploited in the wild

Initial Access and Persistence CVE-2024-55591 and CVE-2025-24472 allow unauthenticated attackers to gain super_admin privileges on vulnerable FortiOS devices (<7.0.16) with exposed management interfaces... Another common exploitation method we observed involved the threat actor using the fortigate-firewall account to exploit CVE-2025-24472 rather than CVE-2024-55591.

via forescoutforescout.com
CVE-2024-55591FortiOS/FortiProxy Management Interface Authentication BypassExploited in the wild

Initial Access and Persistence CVE-2024-55591 and CVE-2025-24472 allow unauthenticated attackers to gain super_admin privileges on vulnerable FortiOS devices (<7.0.16) with exposed management interfaces. A proof-of-concept (PoC) exploit was publicly released on January 27, and within 96 hours, we observed active exploitation in the wild using two distinct methods: jsconsole ... HTTPS ...

via forescoutforescout.com
CVE-2022-41082ProxyNotShell RCE in Microsoft Exchange Server PowerShell

The experts argued that the attackers likely did not exploit recently disclosed CVE-2022-41040 and CVE-2022-41082 vulnerabilities. | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.

via security affairssecurityaffairs.com
CVE-2022-41040ProxyNotShell SSRF in Microsoft Exchange Server

The experts argued that the attackers likely did not exploit recently disclosed CVE-2022-41040 and CVE-2022-41082 vulnerabilities. | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.

via security affairssecurityaffairs.com
CVE-2022-21969RCE in Microsoft Exchange Server (CVE-2022-21969)

Looking at the Microsoft Exchange Server vulnerability history, the remote code execution vulnerability was disclosed on December 16, 2021 (CVE-2022-21969) | In July 2022, two servers operated by a customer of the security firm were infected with LockBit 3.0 ransomware. Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.

via security affairssecurityaffairs.com
CVE-2023-3824PHP PHAR directory entry parsing stack buffer overflowExploited in the wild

According to malware research group vx-underground citing LockBitSupp, the alleged leader of the LockBit operation, law enforcement hacked into the ransomware operation’s servers using a known vulnerability in the popular web coding language PHP. The vulnerability used to compromise its servers is tracked as CVE-2023-3824, a remote execution flaw patched in August 2023, giving LockBit months to fix the bug. | A sweeping law enforcement operation led by the U.K.’s National Crime Agency (NCA) this week took down LockBit, the notorious Russia-linked ransomware gang... It has long been known that LockBit, which first entered the competitive cybercrime scene in 2019, is one of, if not the most prolific ransomware gangs.

via techcrunch com securitytechcrunch.com
CVE-2023-4966CitrixBleed

The GOLD MYSTIC threat group has operated the LockBit name-and-shame ransomware-as-a-service (RaaS) scheme since mid-2019, exploiting unauthorized access to thousands of organizations to deploy ransomware and steal data to facilitate the extortion of victims.

via sophos threat researchsophos.com
CVE-2026-1731Pre-auth OS Command Injection RCE in BeyondTrust Remote Support and PRAExploited in the wild

Researchers at Huntress Security Operations Center (SOC) observed what they call "a sharp uptick" in exploitation activity targeting Bomgar Remote Support (now part of BeyondTrust), with attackers reaching systems through a critical unauthenticated remote code execution (RCE) flaw, CVE-2026-1731.

via dark readingdarkreading.com
CVE-2025-6264Privilege escalation in Rapid7 Velociraptor Admin.Client.UpdateClientConfig artifactExploited in the wild

CVE‑2025‑6264 — Rapid7 Velociraptor Remote Code Execution... Exploitation Status: Actively exploited in ransomware campaigns.

via cyberthronethecyberthrone.in
CVE-2025-49704Remote Code Execution in Microsoft Office SharePointExploited in the wild

Storm-2603... observed stealing MachineKeys and deploying Warlock and Lockbit ransomware... They conduct lateral movement using PsExec and Impacket, deploying Warlock and LockBit ransomware to encrypt systems. | Exploited vulnerabilities include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771, collectively known as ToolShell. CVE-2025-49704: A remote code execution vulnerability allowing attackers to run arbitrary code without authentication.

via polyswarmblog.polyswarm.io
CVE-2025-53771Microsoft SharePoint ToolShell path traversal spoofing vulnerabilityExploited in the wild

Storm-2603... observed stealing MachineKeys and deploying Warlock and Lockbit ransomware... They conduct lateral movement using PsExec and Impacket, deploying Warlock and LockBit ransomware to encrypt systems. | CVE-2025-53771: A ToolShell path traversal vulnerability serving as a security bypass for CVE-2025-49706, facilitating directory traversal and file access.

via polyswarmblog.polyswarm.io
CVE-2025-49706Improper authentication spoofing vulnerability in Microsoft Office SharePointExploited in the wild

Storm-2603... observed stealing MachineKeys and deploying Warlock and Lockbit ransomware... They conduct lateral movement using PsExec and Impacket, deploying Warlock and LockBit ransomware to encrypt systems. | CVE-2025-49706: A spoofing vulnerability enabling post-authentication remote code execution on affected SharePoint servers.

via polyswarmblog.polyswarm.io
CVE-2025-53770ToolShell unauthenticated RCE in Microsoft SharePoint ServerExploited in the wild

CVE-2025-53770: A ToolShell authentication bypass and remote code execution flaw related to CVE-2025-49704, permitting unauthorized command execution. | Storm-2603... observed stealing MachineKeys and deploying Warlock and Lockbit ransomware... They conduct lateral movement using PsExec and Impacket, deploying Warlock and LockBit ransomware to encrypt systems.

via polyswarmblog.polyswarm.io
CVE-2024-37085VMware ESXi Active Directory Integration Authentication Bypass

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
CVE-2024-1708ConnectWise ScreenConnect Path Traversal VulnerabilityExploited in the wild

Affiliates of LockBit ransomware have previously targeted vulnerabilities in ConnectWise ScreenConnect (i.e., CVE-2024-1708 and CVE-2024-1709) for initial access.

via arctic wolf blogarcticwolf.com
CVE-2020-1472ZerologonExploited in the wild

...threat actors have been observed weaponizing a vulnerable version of Bitrix for initial access, followed by using the Zerologon flaw to escalate privileges.

via the hacker newsthehackernews.com
CVE-2024-1709Authentication Bypass in ConnectWise ScreenConnectExploited in the wild

Affiliates of LockBit ransomware have previously targeted vulnerabilities in ConnectWise ScreenConnect (i.e., CVE-2024-1708 and CVE-2024-1709) for initial access.

via arctic wolf blogarcticwolf.com
CVE-2023-46604Apache ActiveMQ OpenWire Remote Code ExecutionExploited in the wild

Attackers leveraged CVE-2023-46604, a remote code execution flaw in the ActiveMQ messaging broker, to break into an exposed Windows server and ultimately encrypt systems via Remote Desktop Protocol — spanning roughly 19 calendar days from initial access to full encryption.

via cyber security newscybersecuritynews.com
CVE-2026-27446Authentication bypass in Apache Artemis Core downstream federation

Reference: https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/

via belgium ccb security advisoriesccb.belgium.be
THREAT ACTORS

Groups observed using it

29 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
GOLD MYSTIC

The GOLD MYSTIC threat group has operated the LockBit name-and-shame ransomware-as-a-service (RaaS) scheme since mid-2019, exploiting unauthorized access to thousands of organizations to deploy ransomware and steal data to facilitate the extortion of victims.

via sophos threat researchsophos.com
LockBit ransomware group

The LockBit ransomware group claimed to have attacked the company’s offices in Tijuana last month... LockBit continues to be one of the most prolific active ransomware groups... operating since September 2019 and was a marginal player before developing a new version of their Ransomware-as-a-Service platform, called LockBit 2.0.

via the record mediatherecord.media
Conti

Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...

via techcrunch com securitytechcrunch.com
PhantomCore

Impact T1486 Data Encrypted for Impact PhantomCore использовали LockBit 3.0 для шифрования трафика

via ptsecurityptsecurity.com
Indrik Spider

Around November 2021, DEV-0243 started to deploy the LockBit 2.0 RaaS payload in their intrusions. ... In a notable shift ... DEV-0401 started deploying LockBit 2.0 ransomware payloads in April 2022.

via microsoft generalmicrosoft.com
Cinnamon Tempest

Around November 2021, DEV-0243 started to deploy the LockBit 2.0 RaaS payload in their intrusions. ... In a notable shift ... DEV-0401 started deploying LockBit 2.0 ransomware payloads in April 2022.

via microsoft generalmicrosoft.com
DEV-0216

Around November 2021, DEV-0243 started to deploy the LockBit 2.0 RaaS payload in their intrusions. ... In a notable shift ... DEV-0401 started deploying LockBit 2.0 ransomware payloads in April 2022.

via microsoft generalmicrosoft.com
Head Mare

LockBit 8F1EF9E7EA31B20FA5EBB4E747003B5C avp.exe

via securelist rusecurelist.ru
LockBit

The LockBit ransomware group, one of the most active ransomware operations in recent years with thousands of attacks to its name, has suffered its own hacking and data leak incident.

via hipaa journalhipaajournal.com
CosmicBeetle

CosmicBeetle, an immature ransomware threat actor using its own signature encryptor, ScRansom, and the leaked LockBit 3.0 builder, became an affiliate of RansomHub.

via eset welivesecurity blogwelivesecurity.com
Wazawaka

According to their posts on Exploit, Wazawaka has worked with at least two different ransomware affiliate programs, including LockBit. Wazawaka said LockBit had paid him roughly $500,000 in commissions for the six months leading up to September 2020.

via krebs on securitykrebsonsecurity.com
Storm-2603

Storm-2603 deployed multiple ransomware types in recent attacks, including LockBit Black and a variant using the .x2anylock extension, linked to the Warlock group.

via securityaffairssecurityaffairs.com
UAC-0238

Groups including UAC-0238 exploited exposed RDP services to push ransomware variants such as X2anylock, Warlock, and LockBit 3.0 into compromised environments.

via cyber security newscybersecuritynews.com
Hastalamuerte

LockBit posted 163 victims in Q1 2026, climbing to fourth place globally.

via checkpoint research blogresearch.checkpoint.com
Lace Tempest

The vulnerability was attributed to Lace Tempest, a Cl0p ransomware affiliate, in April 2023, used in campaigns delivering Cl0p and LockBit ransomware payloads.

via cyberthronethecyberthrone.in
Warlock

...or generated using the leaked LockBit Black builder.

via eset welivesecurity blogwelivesecurity.com
warlock_group

The Warlock Group (aka Storm-2603) is a ransomware gang attributed to Chinese threat actors who utilize the leaked LockBit Windows and Babuk VMware ESXi encryptors in attacks.

via bleeping computerbleepingcomputer.com
Crypt Ghouls

"...deployment of LockBit 3.0 and Babuk ransomware to encrypt victims’ data."

via security online infosecurityonline.info
BlackJack

The attackers used a version of the popular LockBit 3.0 ransomware, compiled from publicly available source code, to encrypt the data.

via the hacker newsthehackernews.com
DragonForce

...delivering various ransomware payloads over the years, including ... LockBit ... ransomware...; ...DragonForce... using a variant of the leaked LockBit3.0 builder...

via the hacker newsthehackernews.com
Storm-0501

...delivering various ransomware payloads over the years, including ... LockBit ... ransomware...; ...DragonForce... using a variant of the leaked LockBit3.0 builder...

via the hacker newsthehackernews.com
Twelve

The attackers used a version of the popular LockBit 3.0 ransomware, compiled from publicly available source code, to encrypt the data.

via the hacker newsthehackernews.com
Storm-1175

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
Storm-0506

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
Scattered Spider

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

via microsoft security blogmicrosoft.com
UNC2465

UNC2465, which used the Darkside and Lockbit ransomware...

via security weeksecurityweek.com
Bl00Dy

Bl00Dy ... used open-source and leaked builders from other operators, including LockBit, Babuk and Conti. From September 2022, the group used the LockBit ransomware builder in its attacks... Similarly, the DragonForce ransomware binary was also revealed to have been likely generated using the LockBit Black builder.

via cyjax blogcyjax.com
Bearlyfy

...Bearlyfy that has used ransomware strains like LockBit 3.0 and Babuk...

via the hacker newsthehackernews.com
WIZARD SPIDER

The LockBit gang began its operation in September 2019 and was first known as “ABCD ransomware.” ... Over the next six months, LockBit worked on a new project, internally referred to as “LockBit Red,” and publicly known as “LockBit 2.0.” ... LockBit officially announced another major release ... LockBit Black (publicly known as LockBit 3.0).

via analyst1 bloganalyst1.com
MITRE ATT&CK

Techniques & procedures

24 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583Acquire InfrastructureEvidence1

authorities disrupted LockBit by seizing numerous public-facing websites used by LockBit to connect to the organization’s infrastructure and by seizing control of servers used by LockBit administrators

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence2

LockBit’s “affiliate” members, including Vasiliev and Astamirov, first identified and unlawfully accessed vulnerable computer systems, and then deployed LockBit ransomware on those systems to both steal and encrypt stored data.

Execution

2 techniques
T1053.005Scheduled TaskEvidence1

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1059.003Windows Command ShellEvidence1
TacticExecution

During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.

Persistence

4 techniques
T1053.005Scheduled TaskEvidence1

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1112Modify RegistryEvidence1

Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.

T1505.003Web ShellEvidence1

Threat actors initially deployed web shell on a compromised Exchange server, then it took just 7 days to escalate privileges to Active Directory admin and stole roughly 1.3 TB of data before encrypting systems hosted in the network.

T1547.001Registry Run Keys / Startup FolderEvidence3

The execution of LockBit was successful, as the following initial automated functions began to execute. However, no files were encrypted... Establish persistence via the registry Run key

T1053.005Scheduled TaskEvidence1

During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.

T1547.001Registry Run Keys / Startup FolderEvidence3

The execution of LockBit was successful, as the following initial automated functions began to execute. However, no files were encrypted... Establish persistence via the registry Run key

T1548.002Bypass User Account ControlEvidence1

Avaddon modifies several registry keys for persistence and UAC bypass. LockBit 2.0 can create Registry keys to bypass UAC and for persistence. Lokibot has modified the Registry as part of its UAC bypass process.

Stealth

4 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.

T1070.001Clear Windows Event LogsEvidence2
TacticStealth

The ransomware binary used also clears key Windows event log files including Application, System and Security.

T1070.004File DeletionEvidence1
TacticStealth

The content repeatedly describes adversaries and malware deleting files, directories, droppers, scripts, logs, archives, staged data, and other artifacts from compromised systems, e.g., 'APT29 has used SDelete to remove artifacts from victim networks' and 'Lazarus Group malware has deleted files in various ways, including "suicide scripts" to delete malware binaries from the victim.'

T1497Virtualization/Sandbox EvasionEvidence1

The new build introduces enhanced evasion and anti-analysis mechanisms, faster encryption routines, and the use of a randomized 16-character file extension to disrupt signature-based detection.

T1112Modify RegistryEvidence1

Across the content, malware repeatedly 'adds Registry Run keys', 'creates Registry entries', 'modifies the Windows Registry', or 'overwrites registry keys' to maintain persistence.

Discovery

3 techniques
T1057Process DiscoveryEvidence1
TacticDiscovery

The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.

T1082System Information DiscoveryEvidence1
TacticDiscovery

The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."

T1497Virtualization/Sandbox EvasionEvidence1

The new build introduces enhanced evasion and anti-analysis mechanisms, faster encryption routines, and the use of a randomized 16-character file extension to disrupt signature-based detection.

Collection

1 technique
T1074Data StagedEvidence3

They threatened to leak the data stolen during the attack by June 11.

T1132Data EncodingEvidence2

C2 traffic from ADVSTORESHELL is encrypted, then encoded with Base64 encoding... APT19 HTTP malware variant used Base64 to encode communications to the C2 server... APT33 has used base64 to encode command and control traffic.

Exfiltration

3 techniques
T1041Exfiltration Over C2 ChannelEvidence2

disrupting the ability of LockBit actors to attack and encrypt networks and extort victims by threatening to publish stolen data

T1537Transfer Data to Cloud AccountEvidence1

When LockBit attacks were successful, LockBit’s affiliate members then demanded ransoms from their victims in exchange for decrypting the victims’ data and then claiming to delete the affiliates’ copies of the data.

T1567Exfiltration Over Web ServiceEvidence1

LockBit ransomware operation claimed the attack on May 31 by publishing a threat to leak data stolen from Foxconn unless a ransom is paid by June 11.

Impact

4 techniques
T1486Data Encrypted for ImpactEvidence16
TacticImpact

According to the investigation, he developed malware in January of this year to obtain illegal profits. The accused intended to use it to encrypt commercial organizations' data and demand a ransom for decryption, Russian prosecutors said.

T1489Service StopEvidence1
TacticImpact

Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. LockBit 3.0 can identify and terminate specific services. RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.

T1490Inhibit System RecoveryEvidence1
TacticImpact

Prevent restoration of the host from backups and recovery states: vssadmin delete shadows /all /quiet wmic shadowcopy delete ... bcdedit /set {default} recoveryenabled no wbadmin delete catalog -quiet

T1657Financial TheftEvidence3
TacticImpact

When victims did not pay the demanded ransoms, LockBit’s affiliates often left the victim’s data permanently encrypted and publish the stolen data, including highly sensitive information, on a publicly accessible internet site under LockBit’s control.

Other

1 technique
T1562.001Disable or Modify ToolsEvidence2

The AuKill tool abuses an outdated version of the driver used by version 16.32 of the Microsoft utility, Process Explorer, to disable EDR processes before deploying either a backdoor or ransomware on the target system.

INDICATORS OF COMPROMISE

IOCs tracked for this family

140 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
45 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
66 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
29 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
hash.sha256●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching140

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution29

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities21

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping24

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.