LockBit — Ransomware Profile
LockBit is a Russia-linked ransomware-as-a-service operation active since 2019 and historically among the most prolific ransomware groups. The February 2024 Operation Cronos takedown disrupted its infrastructure, but the operation reconstituted, releasing LockBit 4.0 on February 3, 2025 with new anti-analysis and evasion features. On May 7, 2025, an unknown intruder defaced its affiliate panels and leaked an internal database exposing roughly 62,000 bitcoin addresses, over 4,400 victim negotiation messages, and affiliate credentials. In September 2025, on the operation's sixth anniversary, it launched LockBit 5.0 with Windows, Linux, and ESXi variants that add DLL reflective loading, ETW patching, post-encryption event log clearing, and randomized 16-character file extensions. Check Point counted 163 LockBit victims in Q1 2026, a 106 percent quarterly increase that returned the group to fourth place among global ransomware operations, with targeting shifting away from the United States.Also tracked as
LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, ABCD ransomware, Water Selkie, Bitwise Spider, LockBit Red, LockBit 4.0, LockBit 5.0
IntelFusions coverage (25)
- Ransomware crew Brain Cipher is back after six quiet weeks 2026-09-01 · Ransomware
- Ransomware claims against Indian firms tripled in a month 2026-08-12 · Cyber Incidents
- Ransomware crew mined crypto in Colombia before encrypting 2026-08-10 · Ransomware
- Latin America's public bodies keep appearing on leak sites 2026-08-08 · Cyber Incidents
- Ransomware hits Brazil's schools using stolen logins 2026-08-03 · Cyber Incidents
- Russian factories hit by new ransomware built for Windows and ESXi 2026-07-30 · Ransomware
- LockBit lists nine fresh victims across Europe despite takedown 2026-07-11 · Ransomware
- Qilin ransomware claims 31 victims in a week across 15 countries 2026-07-11 · Ransomware
- Ransomware gang claims to hit German submarine builder Thyssenkrupp 2026-06-28 · Ransomware
- Newer ransomware crews claim diagnostics maker Hologic and an Australian fire service 2026-06-28 · Ransomware
- Ransomware crew Gentlemen arms affiliates with custom EDR killers 2026-06-19 · Ransomware
- New ransomware crew The Gentlemen claims 20 victims in one week 2026-06-12 · Ransomware
- LockBit floods its leak site with 26 victims in two days 2026-06-12 · Ransomware
- NightSpire: The Rbfs Rebrand That Went From Data Theft to Double Extortion in Weeks 2026-02-16 · Ransomware
- LockBit 5.0 Cross-Platform Analysis: ChaCha20 Encryption, ESXi VM Shutdown Automation, and Near-Zero VirusTotal Detection 2026-02-16 · Ransomware
- LockBit 5.0 Technical Deep Dive: ETW Patching, DLL Reflection Loading, and Cross-Platform ESXi Targeting Confirm Evolutionary Codebase 2026-02-16 · Ransomware
- Poisoned Models, Hijacked Namespaces: How AI Supply Chain Attacks Are Compromising Enterprise ML Pipelines 2026-02-16 · AI Security
- Akira Topped Sophos Ransomware Cases in 2024, Peaked at 17% of August Detections Amid Veeam Exploits 2026-02-16 · Ransomware
- RansomHub (Knight/Cyclops Rebranded): CVE-2024-3400 and ZeroLogon in Sub-14-Hour Attack, PCHunter EDR Termination, FileZilla Exfiltration, and Multi-Platform Ransomware Variants 2026-02-16 · Ransomware
- Eduard Benderskiy Named: The Former KGB Officer Who Shielded Evil Corp from Russian Law Enforcement 2026-02-16 · Cyber Incidents
- U.S. Indicts Dmitry Khoroshev as LockBit's Developer and Administrator: $500M Extorted, 2,500 Victims in 120 Countries 2026-02-16 · Ransomware
- Operation Cronos Fallout: LockBit Admin Panel Exposed, 193 Affiliates Identified, and Post-Disruption Activity Reveals Inflated Victim Counts 2026-02-16 · Ransomware
- From Conti Code to ESXi Servers: SentinelOne Decodes Akira's Cross-Platform Ransomware Evolution 2026-02-16 · Ransomware
- LockBit Green: New Variant Incorporates Leaked Conti Source Code, Revealing Transitivity Links to BazaLoader and TrickBot Families 2026-02-16 · Ransomware
- LockBit Affiliate Side-Loads Cobalt Strike via VMwareXferlogs.exe: Malicious glib-2.0.dll Bypasses EDR Hooks, ETW, and AMSI 2026-02-16 · Ransomware
Tools & malware
- AdFind discovery
- AnyDesk remote access (RMM)
- Cobalt Strike post-exploitation framework
- FileZilla exfiltration / file transfer
- LockBit ransomware
- MEGA exfiltration / cloud storage
- Mimikatz credential theft
- PuTTY Link (Plink) command and control / SSH
- Rclone exfiltration
- StealBit exfiltration tool
Recent claimed victims
- In 1993, Alpha Omega 2026-09-10
- AmorSaúde 2026-09-09
- FDC Putman 2026-09-08
- contreras.com.ar 2026-09-08
- VSB Attorneys Inc 2026-09-07
- For over 60 years, PSC Industries 2026-09-04
- KALA Health 2026-09-04
- Huisartsencentrum Klein Iterson 2026-09-04
- bartelsbv.nl 2026-08-31
- vkj.nl 2026-08-31
- All Steel Products 2026-08-31
- bkc.org 2026-08-31
- Susquehanna Valley Federal Credit Union 2026-08-31
- hoaattorneys.com 2026-08-31
- American Plan Administrators 2026-08-29
- Tennessee Medical Association 2026-08-28
- Heart Center of Memphis 2026-08-27
- DeCe COMPUTERS s.r.o. 2026-08-27
- takt.be 2026-08-27
- FP Management BV 2026-08-27
- ADT 2026-08-23
- Itaguaí Construções Navais S.A. known as ICN, 2026-08-22
- U.S. Bank 2026-08-20
- Terra-Petra 2026-08-18
- Groupe Actua 2026-08-16
Vendor research
- SentinelOne SentinelOne
- #StopRansomware: LockBit 3.0 CISA
- Unveiling the Fallout: Operation Cronos' Impact on LockBit Following Landmark Disruption Trend Micro
- Understanding Ransomware Threat Actors: LockBit CISA
- International investigation disrupts the world's most harmful cyber crime group National Crime Agency
- LockBit ransomware secretly building next-gen encryptor before takedown BleepingComputer
- New LockBit 5.0 Targets Windows, Linux, ESXi Trend Micro
Countries linked to this actor
- Russia origin
- United States targets
- Trinidad and Tobago targets
- Kenya targets
- Paraguay targets