🚀 Introducing the CloudSEK MCP Server!
Read more
In the world of cybercrime, few threat actors have proven as destructive—or as resilient—as the LockBit ransomware gang. Operating as a highly lucrative Ransomware-as-a-Service (RaaS) syndicate, LockBit has extorted billions from organizations worldwide by stealing sensitive data and paralyzing critical infrastructure. Even after a historic multinational law enforcement takedown in 2024, the group has stubbornly refused to disappear. With the emergence of multi-platform variants like LockBit 5.0, understanding how this syndicate operates is no longer optional for enterprise security teams—it is a necessity.Â
According to the FBI and CISA, LockBit was responsible for approximately 1,700 attacks in the United States between January 2020 and May 2023 alone, with victims paying an estimated $91 million in ransom demands.Â
LockBit is a highly evasive Ransomware-as-a-Service (RaaS) operation that steals sensitive enterprise data and encrypts networks to extort victims. Known for its rapid encryption speeds and double-extortion tactics, LockBit targets organizations globally by exploiting unpatched vulnerabilities and compromised credentials.Â
Despite a major law enforcement takedown in February 2024 (Operation Cronos), the group has continually attempted to rebuild, most recently emerging with a "LockBit 5.0" variant in late 2025 and 2026, proving that affiliate activity continues to pose a severe threat.
LockBit operates as a ransomware-as-a-service (RaaS) operation where the core group develops the ransomware, manages payment infrastructure, and maintains dark web leak sites, while affiliates conduct the actual attacks.Â
This affiliate-based structure helped LockBit expand rapidly across global enterprise environments through phishing attacks, stolen credentials, exposed remote access systems, and vulnerability exploitation.
The public face of the operation was a dark web persona known as “LockBitSupp,” who managed affiliate recruitment, public communication, and ransomware operations across cybercrime forums.
In 2024, international law enforcement identified LockBitSupp as Dmitry Yuryevich Khoroshev, a Russian national, during Operation Cronos. In a coordinated international effort, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC), alongside the UK and Australia, imposed sanctions, asset freezes, travel restrictions, and a $10 million reward related to his arrest.
LockBit expanded its operations by recruiting affiliates and Initial Access Brokers (IABs) through Russian-speaking cybercrime forums. Initial Access Brokers specialized in obtaining unauthorized network access through stolen VPN credentials, exposed remote services, or vulnerable systems, which affiliates later used to deploy ransomware inside enterprise environments.
LockBit 3.0 introduced one of the first ransomware bug bounty programs, offering cryptocurrency rewards for identifying flaws in its ransomware infrastructure, dark web portals, encryption mechanisms, and operational security processes.
The program reflected how organized ransomware groups adopted structured development and operational models similar to legitimate technology organizations.
LockBit ransomware follows a multi-stage attack process that combines initial access, lateral movement, data theft, encryption, and extortion across enterprise environments. To understand the mechanics of these attacks, we can map the lifecycle to the MITRE ATT&CK framework:
Attackers gain entry by exploiting external remote services or public-facing applications such as web servers, email gateways, VPNs, and cloud-based platforms. (MITRE: T1133, T1190)
Once inside, affiliates focus on dumping OS credentials and abusing valid accounts to gain administrative rights across the network. (MITRE: T1003, T1078)
The attackers utilize Remote Desktop Protocol (RDP) and Server Message Block (SMB) to traverse the network seamlessly without triggering alarms. (MITRE: T1021.001, T1021.002)
Using custom tools like StealBit or open-source utilities like Rclone, massive volumes of data are siphoned to attacker-controlled servers. (MITRE: T1048, T1567)
The high-speed ransomware payload is deployed, locking files with AES and RSA encryption. (MITRE: T1486)
Attackers issue the ransom note, threatening to leak the exfiltrated data on the LockBit dark web blog if the ransom is not paid promptly.
LockBit affiliates use multiple intrusion techniques to gain access to enterprise systems, bypass security controls, and spread ransomware rapidly across organizational networks.
LockBit ransomware has evolved through multiple versions, with each iteration introducing faster encryption methods, improved evasion techniques, and expanded capabilities.
Emerging in September 2019, the inaugural version was originally known as "ABCD ransomware" because it appended the .abcd extension to encrypted files. It was a foundational build written in C/C++ that established the group's highly automated, self-spreading approach, though it lacked the advanced exfiltration tools seen in later versions.
Released in mid-2021, this version introduced StealBit, a custom, high-speed data exfiltration tool that cemented the group's use of double extortion. Version 2.0 automated lateral movement across enterprise networks by pushing malicious Group Policy Objects (GPOs) from compromised domain controllers to disable Windows Defender and execute the payload across all domain-joined devices simultaneously.
According to ransomware tracking and threat intelligence research, the LockBit 2.0 leak site publicly listed more than 850 victims, while the group’s operators claimed to have compromised at least 12,125 organizations globally during the LockBit 2.0 campaign period.
Debuting in 2022, this highly modular variant incorporated source code from the defunct BlackMatter ransomware. It introduced unprecedented anti-analysis capabilities, requiring a unique 32-character password just to execute the payload (preventing automated sandboxes from analyzing it).
This version also marked the launch of the cybercrime world's first formal "bug bounty" program, paying researchers to find flaws in the LockBit malware.
Spotted in early 2023, this variant integrated leaked source code from the rival Conti ransomware group. It was specifically optimized to target cloud-based environments and virtualized infrastructure, moving away from purely Windows-centric attacks.
This version was actively under development when international law enforcement seized LockBit's infrastructure during Operation Cronos in February 2024. Unlike previous versions written in C/C++, LockBit 4.0 was entirely rewritten in .NET (compiled with CoreRT).
It featured a JSON-based configuration file and three custom encryption modes (AES+RSA: "fast," "intermittent," and "full"), though it lacked the self-propagation features of 2.0 and 3.0. It was largely intercepted before widespread deployment.
Released in September 2025 to coincide with the group's sixth anniversary, this variant represents LockBit's post-takedown rebuild. It is a unified, cross-platform threat featuring dedicated payloads for Windows, Linux, and VMware ESXi servers. It utilizes ChaCha20-Poly1305 encryption, appends randomized 16-character file extensions to hinder recovery, and employs aggressive defense evasion-such as loading via DLL reflection and patching Windows APIs to blind Event Tracing (ETW). Operationally, the group lowered the affiliate buy-in fee to just $500 to rapidly rebuild its hacker network.
LockBit operators indiscriminately target organizations with critical operations, sensitive data, large attack surfaces, and a high operational dependency on digital infrastructure.
Early detection indicators help organizations identify LockBit activity before the ransomware payload spreads widely across enterprise environments.
Organizations can drastically reduce LockBit ransomware risks through stronger identity security, vulnerability management, network segmentation, backup protection, and continuous threat monitoring.
LockBit differs from other operations through its RaaS model, corporate-style management, and extreme encryption speeds.
International law enforcement operations have aggressively targeted LockBit infrastructure to disrupt their operations globally.
In February 2024, a multinational task force (including the NCA, FBI, and Europol) seized LockBit's infrastructure, source code, and decryption keys.
Law enforcement replaced the main LockBit dark web portal with splash pages detailing their infiltration and took control of the StealBit exfiltration network.
Authorities issued sanctions and indictments against key operators, including the alleged Russian national behind the moniker "LockBitSupp."
The FBI and international partners released official LockBit 3.0 decryptors via the "No More Ransom" portal to help victims recover data without paying.
Following the takedown, many LockBit affiliates scattered to rival groups (like RansomHub). However, the core developers launched new infrastructure and released updated variants (like LockBit 5.0) in an attempt to salvage their brand and resume operations in 2025 and 2026.
RaaS is a business model where the core developers maintain the ransomware software, payment portals, and leak sites, leasing the tools out to independent "affiliates." These affiliates conduct the actual cyberattacks and share a percentage of the final ransom payment with the developers.
Yes. Following Operation Cronos in 2024, international law enforcement agencies released free decryption tools for certain LockBit 3.0 victims. These tools are available through the official No More Ransom project portal.
Yes. LockBit heavily utilizes a double extortion tactic. Affiliates use custom tools to exfiltrate sensitive data before locking the files, threatening to publish the data on their dark web leak sites to force the victim into paying.
Coverage varies heavily by policy. While some cyber insurance policies cover ransom payments and recovery costs, many carriers now require proof of strict security controls (like MFA and EDR) to validate a claim. Furthermore, payments are strictly prohibited by law if the attackers are associated with entities on government sanctions lists (such as OFAC).
Yes. While Operation Cronos severely disrupted their infrastructure and brand trust, the group's administrators have continuously attempted to rebuild. They have launched new dark websites and released updated variants like LockBit 5.0, meaning organizations must remain vigilant.
A vulnerable web applications can open the door to your critical assets. Stay protected with CloudSEK BeVigil Enterprise Web App Scanner module.
Schedule a Demo