LockBit Green is a ransomware variant associated with the LockBit ransomware-as-a-service ecosystem and identified in early 2023 as a derivative built largely from leaked Conti source code rather than a wholly original LockBit codebase. It has been described as a successor line alongside earlier LockBit variants such as LockBit Red and LockBit Black, and was made available to affiliates through the LockBit builder infrastructure.
Technical analysis has found substantial code overlap with Conti v3, including identical command-line options and only limited modifications relative to the leaked Conti implementation. The ransom note format closely follows LockBit Black branding, indicating that the variant combines LockBit operational packaging with Conti-derived encryption logic. Reporting also indicates that LockBit operators adapted the variant for cloud-oriented targeting, including ESXi-related use cases, expanding its relevance beyond traditional Windows enterprise environments.
LockBit Green should be understood as part of the broader post-Conti fragmentation of the ransomware landscape, in which leaked Conti code enabled rapid development or rebranding by multiple criminal operations. Its emergence illustrates how established ransomware groups can reuse mature code from defunct or disrupted rivals to accelerate releases, reduce development effort, and maintain affiliate interest. The malware is tied to financially motivated extortion activity characteristic of LockBit operations, including encryption of victim systems and pressure to pay for recovery and to avoid data exposure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lockbit ransomware operators have implemented a new version of their malware, dubbed LockBit Green, which was designed to include cloud-based services among its targets.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conti-based ransomware variant referenced as sharing a mutex naming convention with DragonForce.
2023年1月に確認されたLockBit系検体として言及されるが、本文ではContiをもとに作成された非オリジナル版と説明されている。
A LockBit variant reportedly discovered in January 2023 and believed to be built from leaked Conti source code.
A new LockBit ransomware variant available to LockBit RaaS affiliates via the builder feature. It targets cloud-based services and appears to be derived largely from leaked Conti v3 source code, with only limited modifications such as the ransom note.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.