Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lockbit

Description

LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions. Known victims: 5 5 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

LockBit is a highly sophisticated criminal ransomware group operating as a Ransomware-as-a-Service (RaaS) platform. Known for its prolific activity, LockBit has been linked to numerous high-profile ransomware incidents globally. The group primarily focuses on financial gain through the encryption and subsequent decryption of victims' data in exchange for cryptocurrency payments. Operating with a structured affiliate model, LockBit has demonstrated significant adaptability and targeting precision across multiple sectors.

Goals & Targeting

LockBit's primary strategic objective is financial gain through the deployment of ransomware. The group targets a wide range of sectors due to their affiliate model, which allows them to focus on high-value victims regardless of industry. Their targeting profile includes entities in healthcare, education, manufacturing, and government, as these often have valuable data or limited defenses. Affiliates are incentivized through a revenue-sharing model, making LockBit's operations both scalable and effective. The group's global reach is facilitated by its decentralized structure and the use of sophisticated tools to avoid detection while maximizing payout potential.

Enhanced Description

LockBit operates one of the most successful ransomware-as-a-service (RaaS) platforms globally. The group leverages an affiliate network to conduct intrusions, allowing developers to maintain infrastructure while affiliates execute attacks. This model has made LockBit responsible for a staggering 44% of all ransomware incidents in 2023, according to some sources. Targeting virtually every sector worldwide, LockBit's campaigns have been characterized by their precision and efficiency. The group employs a range of tactics, techniques, and procedures (TTPs) to achieve its objectives, including the use of custom ransomware variants such as HappyMackerel. Notably, LockBit has demonstrated a strong focus on maximizing profits through high-value targets and leveraging affiliate relationships for global reach.

Key Capabilities

  • Ransomware-as-a-Service (RaaS) platform
  • Affiliate recruitment and management
  • Custom ransomware variants like HappyMackerel
  • Sophisticated encryption methods
  • Leveraging dark web infrastructure for communication
  • Targeted phishing campaigns
  • Use of legitimate tools for lateral movement

MITRE ATT&CK Tactics

Initial Access
Lateral Movement
Data Exfiltration
Defense-Evasion
Credential Access

ATT&CK Techniques

T1059.003
T1055
T1566.001
T1078
T1021
T1197
T1543

Software / Tooling

LockBit Ransomware family (e.g., HappyMackerel)
PowerShell scripts for execution
Dark web communication channels
Tor network usage
Cobalt Strike-like frameworks

Campaigns & Victims

LockBit's campaigns are marked by their rapid operational tempo and precision targeting. The group has been particularly active in the healthcare, education, and manufacturing sectors, leveraging their affiliate network to maximize geographic and sectoral coverage. Notable past operations include attacks on European hospitals, U.S. educational institutions, and Asian manufacturing firms. LockBit's use of double extortion tactics—encrypting data and threatening to leak it unless a ransom is paid—has further increased its notoriety. The group's ability to adapt to new defenses and exploit zero-day vulnerabilities has contributed to their sustained success in the ransomware landscape.

IOC Patterns

  • Spear-phishing emails featuring malicious .zip or .exe attachments
  • Use of TTY (e.g., /dev/tty) enumeration techniques in scripts
  • Lateral movement using tools like psinfo.exe or WMI
  • Encrypted files with extensions such as .locked or .enc
  • Ransomware notes left in folders (e.g., README.txt)
  • Exfiltration of data via webmail services or cloud storage
  • Presence of custom loaders and droppers

Recommended Actions

  • Implement endpoint detection and response (EDR) solutions to monitor for LockBit's TTPs.
  • Conduct regular phishing simulations to train employees on identifying suspicious emails.
  • Maintain offline backups of critical systems and regularly test restoration processes.
  • Monitor network traffic for indicators of unauthorized data exfiltration or command-and-control communication.
  • Patch systems promptly to mitigate the risk of exploitation through known vulnerabilities.
  • Use multi-factor authentication for sensitive accounts to prevent credential-based attacks.

Suggested Tags

Ransomware
Crime
Financial Gain
Healthcare Sector
Education Sector
Manufacturing
Double Extortion

Confidence Assessment

High confidence in LockBit's operational capabilities, targeting strategies, and known TTPs. Available intelligence suggests the group has a robust infrastructure and a proven track record of successful campaigns. However, gaps exist in understanding specific tools used and exact kill chains employed in their operations, which limits the completeness of the analysis.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

13

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Crime
Financial Gain
Healthcare Sector
Education Sector
Manufacturing
Double Extortion

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Oct 21, 2020
Last Seen
Aug 23, 2021
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.