LockBit — Ransomware Profile

LockBit is a Russia-linked ransomware-as-a-service operation active since 2019 and historically among the most prolific ransomware groups. The February 2024 Operation Cronos takedown disrupted its infrastructure, but the operation reconstituted, releasing LockBit 4.0 on February 3, 2025 with new anti-analysis and evasion features. On May 7, 2025, an unknown intruder defaced its affiliate panels and leaked an internal database exposing roughly 62,000 bitcoin addresses, over 4,400 victim negotiation messages, and affiliate credentials. In September 2025, on the operation's sixth anniversary, it launched LockBit 5.0 with Windows, Linux, and ESXi variants that add DLL reflective loading, ETW patching, post-encryption event log clearing, and randomized 16-character file extensions. Check Point counted 163 LockBit victims in Q1 2026, a 106 percent quarterly increase that returned the group to fourth place among global ransomware operations, with targeting shifting away from the United States.

Also tracked as

LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, ABCD ransomware, Water Selkie, Bitwise Spider, LockBit Red, LockBit 4.0, LockBit 5.0

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions