← All ransomware groups

Ransomware group profile · #247 by claimed victims

LockBit ransomwarealso LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green

For several years the highest-volume ransomware-as-a-service operation in the world, run as a deliberately commercial affiliate programme with marketing, a bug bounty, and a brand its operator defended in public. Its scale came from making affiliate onboarding easy rather than from technical sophistication: the tooling is largely off the shelf.

Disrupted Russia First seen Sep 2019 ATT&CK G1015 AES per file with RSA wrapped key; partial encryption of the first blocks for speed Russian
5Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
4Countries hit
2Leak-site URLs tracked, 0 online
23 Aug 2021Latest claim recorded

Victimology

Who LockBit claims to have breached, from 5 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Technology2
Transportation2
Manufacturing1

Top countries

Thailand1
Switzerland1
United Kingdom1
India1

Latest claimed victims 5 most recent

VictimSectorCountryClaimed
Bangkok Airways Transportation TH 23 Aug 2021
Accenture Technology 30 Jul 2021
Merseyrail (Rail network) Transportation GB 1 Apr 2021
Kopter Manufacturing CH 30 Nov 2020
Press Trust of India (PTI) Technology IN 21 Oct 2020

All 5 LockBit victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

12 MITRE ATT&CK techniques mapped to LockBit from public advisories and VULONE's own analysis.

TacticTechniqueProcedureConfidence
Initial Access T1133 External Remote Services RDP and VPN with valid credentials bought from access brokers, frequently on the same forums this platform indexes. Confirmed
Initial Access T1190 Exploit Public-Facing Application Exploited internet-facing appliances at scale, including Citrix NetScaler (CVE-2023-4966, "Citrix Bleed"), Fortinet VPNs and Log4Shell. Affiliates were given wo… Confirmed
Execution T1059.003 Windows Command Shell Batch files to chain the pre-encryption steps: stop services, delete shadows, clear logs, then run the locker. Confirmed
Credential Access T1003.001 LSASS Memory Mimikatz and comparable tooling for credential dumping after local admin was obtained. Confirmed
Discovery T1046 Network Service Discovery SoftPerfect Network Scanner and Advanced IP Scanner to enumerate reachable hosts and shares. Confirmed
Lateral Movement T1021.001 Remote Desktop Protocol RDP between hosts with harvested credentials, and PsExec or Cobalt Strike where RDP was not available. Confirmed
Command and Control T1219 Remote Access Tools AnyDesk, TeamViewer, Splashtop and Atera as durable access alongside the beacon. Confirmed
Exfiltration T1567.002 Exfiltration to Cloud Storage StealBit, a custom exfiltration tool given to affiliates, alongside Rclone, MEGA and FreeFileSync. StealBit exists because affiliates were slow to exfiltrate, a… Confirmed
Impact T1486 Data Encrypted for Impact Partial encryption of the leading blocks of each file, which is fast enough that the run often completes before anyone reacts. Confirmed
Impact T1490 Inhibit System Recovery Shadow copies deleted and boot recovery disabled before encryption. Confirmed
Impact T1491.001 Internal Defacement Desktop wallpaper replaced with the ransom notice, and where a printer was reachable, the note was printed repeatedly. Confirmed
Defense Evasion T1562.001 Disable or Modify Tools Disabled endpoint protection before the encryptor ran, using both native tooling and purpose-built EDR killers that abuse signed vulnerable drivers. Confirmed

Tooling observed

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Attack playbook

How a typical LockBit intrusion unfolds, section by section.

Initial access

Bought access, not clever access — The dominant route in is a valid credential or an unpatched appliance, both bought. Negotiation transcripts repeatedly show affiliates who did not know how their own access was obtained.

Operational security

A brand that outlived its security — The operator maintained a public persona and gave interviews, and affiliate identifiers and payment addresses were recorded internally. Roughly 60,000 bitcoin addresses are a durable pivot: they connect affiliate account…

Negotiation and extortion

A pricing ladder tied to revenue — Negotiation transcripts show an opening demand set against estimated revenue and insurance, with defined discount steps and a deadline that is extended more readily than the public posture suggests. Roughly 4,400 convers…

Organisation

An affiliate programme with marketing — LockBit competed for affiliates rather than victims: it ran a bug bounty, published a comparison of its encryption speed against rivals, and paid affiliates before taking its own cut, which was unusual and attractive. Th…

Frequently asked

Is LockBit ransomware still active?
LockBit is tracked as disrupted. The most recent leak-site claim VULONE recorded is dated 23 August 2021.
How many victims has LockBit claimed?
VULONE has recorded 5 leak-site victim claims attributed to LockBit since October 2020, across 4 countries and 3 sectors.
Which industries does LockBit target?
The sectors most often named on the LockBit leak site are Technology, Transportation, Manufacturing.
Which countries are most affected by LockBit?
Most LockBit victims recorded by VULONE are located in Thailand, Switzerland, United Kingdom.
Where does VULONE get LockBit victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Public sources

TitlePublisherDate
VULONE primary-source researchVULONE7 May 2025
Operation CronosNCA / FBI / Europol20 Feb 2024
Understanding Ransomware Threat Actors: LockBit (AA23-165A)CISA and international partners14 Jun 2023

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].