Ransomware group profile · #247 by claimed victims
LockBit ransomwarealso LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green
For several years the highest-volume ransomware-as-a-service operation in the world, run as a deliberately commercial affiliate programme with marketing, a bug bounty, and a brand its operator defended in public. Its scale came from making affiliate onboarding easy rather than from technical sophistication: the tooling is largely off the shelf.
Victimology
Who LockBit claims to have breached, from 5 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 5 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| Bangkok Airways | Transportation | TH | 23 Aug 2021 |
| Accenture | Technology | — | 30 Jul 2021 |
| Merseyrail (Rail network) | Transportation | GB | 1 Apr 2021 |
| Kopter | Manufacturing | CH | 30 Nov 2020 |
| Press Trust of India (PTI) | Technology | IN | 21 Oct 2020 |
All 5 LockBit victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
12 MITRE ATT&CK techniques mapped to LockBit from public advisories and VULONE's own analysis.
| Tactic | Technique | Procedure | Confidence |
|---|---|---|---|
| Initial Access | T1133 External Remote Services | RDP and VPN with valid credentials bought from access brokers, frequently on the same forums this platform indexes. | Confirmed |
| Initial Access | T1190 Exploit Public-Facing Application | Exploited internet-facing appliances at scale, including Citrix NetScaler (CVE-2023-4966, "Citrix Bleed"), Fortinet VPNs and Log4Shell. Affiliates were given wo… | Confirmed |
| Execution | T1059.003 Windows Command Shell | Batch files to chain the pre-encryption steps: stop services, delete shadows, clear logs, then run the locker. | Confirmed |
| Credential Access | T1003.001 LSASS Memory | Mimikatz and comparable tooling for credential dumping after local admin was obtained. | Confirmed |
| Discovery | T1046 Network Service Discovery | SoftPerfect Network Scanner and Advanced IP Scanner to enumerate reachable hosts and shares. | Confirmed |
| Lateral Movement | T1021.001 Remote Desktop Protocol | RDP between hosts with harvested credentials, and PsExec or Cobalt Strike where RDP was not available. | Confirmed |
| Command and Control | T1219 Remote Access Tools | AnyDesk, TeamViewer, Splashtop and Atera as durable access alongside the beacon. | Confirmed |
| Exfiltration | T1567.002 Exfiltration to Cloud Storage | StealBit, a custom exfiltration tool given to affiliates, alongside Rclone, MEGA and FreeFileSync. StealBit exists because affiliates were slow to exfiltrate, a… | Confirmed |
| Impact | T1486 Data Encrypted for Impact | Partial encryption of the leading blocks of each file, which is fast enough that the run often completes before anyone reacts. | Confirmed |
| Impact | T1490 Inhibit System Recovery | Shadow copies deleted and boot recovery disabled before encryption. | Confirmed |
| Impact | T1491.001 Internal Defacement | Desktop wallpaper replaced with the ransom notice, and where a printer was reachable, the note was printed repeatedly. | Confirmed |
| Defense Evasion | T1562.001 Disable or Modify Tools | Disabled endpoint protection before the encryptor ran, using both native tooling and purpose-built EDR killers that abuse signed vulnerable drivers. | Confirmed |
Tooling observed
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Attack playbook
How a typical LockBit intrusion unfolds, section by section.
Initial access
Bought access, not clever access — The dominant route in is a valid credential or an unpatched appliance, both bought. Negotiation transcripts repeatedly show affiliates who did not know how their own access was obtained.
Operational security
A brand that outlived its security — The operator maintained a public persona and gave interviews, and affiliate identifiers and payment addresses were recorded internally. Roughly 60,000 bitcoin addresses are a durable pivot: they connect affiliate account…
Negotiation and extortion
A pricing ladder tied to revenue — Negotiation transcripts show an opening demand set against estimated revenue and insurance, with defined discount steps and a deadline that is extended more readily than the public posture suggests. Roughly 4,400 convers…
Organisation
An affiliate programme with marketing — LockBit competed for affiliates rather than victims: it ran a bug bounty, published a comparison of its encryption speed against rivals, and paid affiliates before taking its own cut, which was unusual and attractive. Th…
Frequently asked
Is LockBit ransomware still active?
How many victims has LockBit claimed?
Which industries does LockBit target?
Which countries are most affected by LockBit?
Where does VULONE get LockBit victim data?
Public sources
| Title | Publisher | Date |
|---|---|---|
| VULONE primary-source research | VULONE | 7 May 2025 |
| Operation Cronos | NCA / FBI / Europol | 20 Feb 2024 |
| Understanding Ransomware Threat Actors: LockBit (AA23-165A) | CISA and international partners | 14 Jun 2023 |
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].