LockBit Green: New Variant Incorporates Leaked Conti Source Code, Revealing Transitivity Links to BazaLoader and TrickBot Families

GLIMPS researchers documented in an analysis published on GLIMPS the emergence of LockBit Green — a new LockBit variant built on the leaked Conti ransomware source code. Three samples from the same campaign were submitted to the GLIMPS Malware analysis platform, with the Deep Engine detecting cross-family code similarities confirming that LockBit incorporated Conti's 2022 leaked codebase into their own ransomware, continuing a pattern of opportunistic code reuse observed across multiple ransomware families following the Conti source leak.

The Conti Code Leak: A Shared Resource for Multiple Groups

Conti ransomware emerged in 2020 and rapidly became one of the most prolific RaaS operations, with high-profile victims including Ireland's Health Service Executive (HSE) in May 2021. Internal documents leaked in 2021 by a disgruntled affiliate, and in 2022 — following Conti leadership's public support for Russia in the Ukraine invasion — a full source code leak was published online. LockBit exploited this leak to incorporate Conti code into their own ransomware, producing LockBit Green. The same code also influenced BazaLoader, creating a triangular code-sharing relationship: LockBit Green and BazaLoader both derive independently from the leaked Conti codebase, while TrickBot elements appear in samples due to TrickBot's established relationship with the Conti group's operational toolkit.

Three-Sample Analysis: Deep Engine Cross-Family Correlations

The first sample (45c317200e27e5c5692c59d06768ca2e7eeb446d6d495084f414d0f261f75315) was identified as malicious by GLIMPS Malware's Deep Engine, which detected embedded functions used in both Conti and LockBit family binaries. Sandbox dynamic analysis confirmed active ransomware behavior. The second sample (FB49B940570CFD241DEA27AE768AC420E863D9F26C5D64F0D10AEA4DD0BF0CE3) extended the cross-family correlations to include TrickBot and BazaLoader alongside Conti and LockBit — explained by TrickBot's operational role within the Conti group and BazaLoader's independent incorporation of the same leaked Conti code, demonstrating code-sharing transitivity rather than direct organizational links. The third sample (924ec909e74a1d973d607e3ba1105a17e4337bd9a1c59ed5f9d3b4c25478fe11) confirmed the same family correlations and additionally yielded extracted .onion links beginning with a LockBit string — consistent with LockBit's ransom payment portal infrastructure — and a recoverable ransom note via dynamic analysis.

LockBit Green Behavioral Indicators: Random Extensions, Conti-Derived Note Structure

Unlike earlier LockBit versions that appended a static .lockbit extension, LockBit Green encrypts files with randomized character string extensions — a behavior confirmed in sandbox analysis of the third sample. The ransom note structure mirrors LockBit v3 (LockBit Black), maintaining visual and operational consistency with the broader LockBit brand while the underlying encryption engine derives from Conti code. The combination of a new code foundation (Conti), consistent branding (LockBit Black ransom note format), and updated evasion characteristics (randomized extensions) reflects LockBit's strategy of continuous technical evolution while preserving the victim interaction model affiliates are familiar with.

Detection coverage

Read the full analysis on IntelFusions