LockBit 3.0 is a ransomware variant identified in the provided reporting as one of the most commonly observed ransomware families. It was cited by ENISA as one of the most common ransomware variants affecting the public sector in 2024, alongside RansomHub and 8Base. Separate Q1 2023 reporting listed LockBit 3.0 among the most commonly observed ransomware variants by market share at 6.3%. The broader reporting context describes a resurgence of big-game-hunting ransomware during Q1 2023, with increased attacks against large enterprises, more catastrophic encryption and business interruption, and a growing tendency across the ransomware ecosystem to target larger organizations. The same reporting notes that email phishing was the most observed ransomware initial access vector in Q1 2023 and maps common ransomware behaviors to MITRE ATT&CK techniques including data encryption for impact, service stopping, data destruction, resource hijacking, remote services, lateral tool transfer, clearing Windows event logs, process injection, defense impairment, exfiltration over web services, remote access software, ingress tool transfer, and multi-hop proxying. Public sector entities mentioned in the reporting as heavily affected by cyber threats included municipal websites and government ministry portals. No LockBit-3.0-specific infection chain, actor attribution, or indicators of compromise were directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A major ransomware variant that encrypts files and demands ransom, frequently used in attacks against public sector organizations.
A major Ransomware-as-a-Service variant, Lockbit 3.0 is widely used in attacks against enterprises, featuring both encryption and data theft extortion tactics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.