LockBit
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
LockBit is a ransomware operation that operates under the aliases LockBit, LockBit 2.0 and LockBit 3.0 and has been linked to Russian‑based threat actors. The group has targeted a wide range of sectors including banking, healthcare, government agencies, manufacturing, education and critical infrastructure across multiple regions such as Senegal, France, Germany, the United States, Australia, Italy and South Korea. Its primary objective is financial gain through ransom demands, employing a double‑extortion model that encrypts victim data and threatens to publish stolen information if payment is not made, which frequently results in operational disruption of services such as banking networks, hospital systems and municipal operations.
The ransomware itself is the LockBit malware family, which is noted for its ability to self‑propagate within a network once initial access is achieved. Initial access vectors observed in reported incidents include phishing emails with malicious links, exploitation of unpatched vulnerabilities, compromised third‑party suppliers, exposed Remote Desktop Protocol services and rogue devices such as a Windows 7 PC used for manufacturing equipment. LockBit 3.0 introduces additional capabilities such as a leak site with a countdown timer, options for victims to pay to extend the countdown, to delete all exfiltrated data or to download the stolen data, a bug‑hunting platform for its infrastructure and the ability to purchase cryptocurrency. The group follows a ransomware‑as‑a‑service model where affiliates conduct the attacks and receive up to three‑quarters of the ransom payment, while the core developers retain the remainder. LockBit has been described as part of the malware family that includes LockerGoga and MegaCortex and has been linked publicly to other Russia‑affiliated ransomware cartels such as Conti, Black Basta, DarkSide, BlackMatter and BlackCat/ALPHV.
Attribution to Russia is repeatedly mentioned in open‑source reporting, with the group’s alleged leader nicknamed LockBitSupp noted to reside in Russia and to use services such as SpaceX’s Starlink to obscure his network location. Notable campaigns that illustrate the group’s reach include the 2024 ransomware attack on Banque de l’Habitat du Sénégal that compromised half a million client records, the 2023 incident against the French regional council’s economic development agency that prompted nationwide cyber‑security mobilization, the 2023 breach of Evolve Bank & Trust following a phishing click, the 2023 ransomware strike on the Community Clinic of Maui that exposed over 120 000 individuals’ medical data, the 2023 TSMC supply‑chain incident involving a third‑party IT provider, the 2023 attack on Bank Syariah Indonesia that resulted in the publication of 1.5 terabytes of customer data, and the 2023 LockBit claim against the Washington County Sheriff’s Office in Florida. Law‑enforcement actions have disrupted LockBit’s infrastructure and led to arrests of affiliates, yet the group continues to adapt and claim new victims worldwide.
Incidents
Attributed incidents are available to members.
198 incidents