Cyber Threat Actor: LockBit
| Actor Type | Location | Known Incidents |
Crime Syndicate
|
—
|
0 incidents |
|---|
Characteristics
Profile
The threat actor known as LockBit, which also used the early alias ABCD, operates as a ransomware‑as‑a‑service (RaaS) group that has been active since September 2019 and is believed to be based in Russia according to multiple reporting sources. The group’s structure involves a core development team that creates the LockBit malware and affiliates who deploy it in exchange for a share of ransom payments, typically up to three‑quarters of the proceeds. LockBit has been observed using the moniker LockBit 3.0 to denote its latest platform, which includes additional monetization options such as paying to extend a publication countdown, to delete stolen data, or to obtain exclusive access to exfiltrated files.
LockBit’s victims span a wide range of sectors and geographic regions, reflecting a financially motivated, opportunistic targeting strategy. Reported incidents include a UK fencing manufacturer (Zaun), an Italian industrial firm (STIM Group), a Taiwanese semiconductor supplier linked to TSMC, an Indonesian state‑owned bank (BSI), the Royal Dutch Football Association, South Korea’s National Tax Service, a major U.S. dental insurer (MCNA), an office‑products distributor (Essendant), a Japanese audio equipment maker (Audio‑Technica), numerous Italian companies across manufacturing, logistics and chemicals, U.S. school districts, hospitals in Belgium, Brazil and France, churches in the United States and law‑enforcement agencies such as a Florida sheriff’s office. The group’s public statements consistently tie ransom demands to the victim’s revenue and the volume or type of data taken, and they employ a double‑extortion model that threatens to leak stolen information if payment is not made.
Technical details described in the sources show that LockBit gains initial access through various vectors, including compromised third‑party suppliers, exposed or outdated systems such as a rogue Windows 7 PC, phishing emails that impersonate trusted contacts, and inadequately secured Remote Desktop Protocol services that should be protected by a VPN. Once inside a network, the actors deploy the LockBit ransomware to encrypt files while simultaneously exfiltrating data for leverage. The group’s data‑leak site features a countdown clock to pressure victims, and it offers paid services to extend the deadline, destroy the leaked data, or download the full stolen dataset. Payments are demanded in cryptocurrencies, principally Bitcoin or Monero, and the gang’s communications often include threats to publish passwords, network entry points and other sensitive details.
Representative operations that illustrate the group’s activity include the LockBit claim against Zaun where a vulnerable Windows 7 machine was the entry point, the alleged TSMC breach traced to a supplier named Kinmax Technology, the publication of 1.5 TB of data from Indonesia’s BSI Bank after failed ransom talks, the leak of employee data from the Royal Dutch Football Association, the exposure of personal information from nearly nine million individuals in the MCNA incident, the network outage at Essendant that was later confirmed as ransomware‑related, and the addition of Audio‑Technica to the leak site with a countdown to data release. Additional examples cited in Italian‑language reports detail attacks on companies such as Comacchio, Errebielle, Gruppo Mercurio, Tecnosys Italia, Lubrimetal and Bontà Viva, as well as incidents affecting school districts in New Jersey and New York, hospitals in Europe and various religious and governmental entities. These cases demonstrate the actor’s reliance on ransomware, data exfiltration and extortion tactics while highlighting the broad scope of its observed campaigns.
