Researchers reported a new LockBit 4.0 ransomware line, including the LockBit 4 Green variant, with fresh indicators of compromise and updated operational tooling. Public reporting tied the release to December 2024 and published two executable hashes, multiple hashes for three associated PowerShell script families, ten IP addresses allegedly contacted by those scripts, and a broad set of Tor .onion domains linked to LockBit infrastructure. The reporting also said the malware uses a new ransom note and introduced 12 new PowerShell files that defenders can use for detection and threat hunting.
Technical analysis of LockBit 4 Green showed a packed 64-bit executable that decrypts a second-stage payload from the .data section and relies on importless execution with API hashing, XOR-based string decryption, and proxy DLL loading via RtlQueueWorkItem. The ransomware also employed multiple defense-evasion measures, including ETW patching, removal of DLL notifications, module unhooking, and clearing vectored exception handlers, while checking for Russian language settings and system architecture before execution. Once active, it disabled Volume Shadow Copy and Windows Search-related functionality, applied file and path exclusions, and used partial encryption that encrypted all files smaller than 1 MB while encrypting roughly 27% of larger files.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
A separate analysis examines the LockBit 4 Green variant's unpacking, API hashing, string decryption, proxy DLL loading, anti-monitoring techniques, and operational behaviors such as service disabling and partial encryption logic.
Analysis of the LockBit 4 Green variant states it is a newer version announced by the LockBit group in December 2024. This marks the emergence of the LockBit 4 line referenced by the later technical reporting.
A threat-intelligence style post claims LockBit 4.0 had recently been released and publishes indicators including executable hashes, PowerShell script hashes, contacted IP addresses, Tor onion domains, and notes about a new ransom note and 12 new PowerShell files.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 78 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.