LockBit was the most active ransomware group globally in 2022 by victims claimed on its leak site and remained prolific into 2023, according to a joint advisory from CISA, the FBI, and international partners. Fortinet attributed approximately half of its 3,298 observed ransomware incidents in 2022 to LockBit, while the FBI estimated roughly 1,700 U.S. attacks and $91 million in ransom payments since early 2020. Its ransomware-as-a-service operation enables loosely connected affiliates to steal data and typically encrypt systems, demanding payment for decryption and to prevent publication of stolen information. The malware evolved from ABCD in 2019 through LockBit Red, Black, and Conti-derived Green, with macOS-targeting encryptor samples observed in 2023.
Affiliates use varied intrusion methods, including exploitation of vulnerabilities such as Log4Shell and PaperCut flaws, exposed RDP, phishing, drive-by compromise, and access purchased from initial access brokers. They combine custom tools such as StealBit with legitimate remote-access and other dual-use utilities for credential theft, lateral movement, defense evasion, and exfiltration. The advisory and Fortinet report emphasize patching exploited vulnerabilities, securing remote access, maintaining secure backups, and testing layered defenses against documented ATT&CK techniques. Authorities encourage incident reporting and discourage ransom payments; organizations should prepare for both operational disruption and stolen-data extortion.

TTPs, infrastructure, and targeting history in one profile.
14 events from the most recent confirmed update back to the earliest known activity.
CISA, the FBI, MS-ISAC, and international partners released an advisory detailing LockBit's evolution, affiliate tactics, exploited vulnerabilities, and recommended defenses. It identified LockBit as the most active global ransomware group in 2022 by victims claimed on its leak site and reported FBI estimates of about 1,700 U.S. attacks and $91 million in ransom payments since 2020.
LockBit ransomware samples targeting macOS were submitted to and observed on VirusTotal, extending the operation's observed platform coverage beyond Windows, Linux, and ESXi.
LockBit Green appeared using an encryption tool based on leaked Conti source code. It used random eight-character encrypted-file extensions and !!!-Restore-My-Files-!!!.txt ransom notes.
The LockBit 3.0 builder was leaked, enabling actors outside LockBit's affiliate program to use the ransomware.
LockBit 3.0, also called LockBit Black, appeared with random nine-character encrypted-file extensions and new ransom-note naming. It added web mirrors, Tox and Jabber communication options, and advertisements recruiting insiders with corporate information or network access.
A late-2022 post offered to purchase Raccoon Stealer source code. FortiGuard Labs cited the offer as suggesting interest in incorporating existing information-stealing code into LockBit.
Reported distributed denial-of-service attacks took LockBit's leak sites offline in mid-2022.
The LockBit developer introduced LockBit Linux-ESXi Locker 1.0 to target Linux and VMware ESXi systems. The variant encrypted files and left a restore-my-files.txt ransom note.
LockBit 2.0, also called LockBit Red, appeared with the built-in StealBit information-stealing tool. It retained the .lockbit extension and added a website accessible through ordinary browsers.
LockBit affiliates began combining data encryption with exfiltration, threatening to publish stolen information on leak sites to pressure victims into paying.
The joint advisory identifies January 5, 2020, as the date LockBit activity was first observed in the United States.
ABCD was rebranded as LockBit, with LockBit-named ransomware appearing on Russian-language cybercrime forums. The rebranding introduced the .lockbit encrypted-file extension and centralized victim communication on a Tor website.
ABCD ransomware was first observed in September 2019. Early versions used email-based victim communication and deleted shadow copies.
FortiGuard Labs reported an apparently earlier ABCD sample whose ransom note contained only a victim ID, along with a transitional sample using LockBit branding while retaining the .abcd extension. Its technical report also supplied SHA-256 indicators for multiple ransomware generations and Linux and macOS samples.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 58 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.