LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions. Known victims: 5 5 ransom note(s) on file
Objectives
Executive Summary
LockBit is a highly sophisticated criminal ransomware group operating as a Ransomware-as-a-Service (RaaS) platform. Known for its prolific activity, LockBit has been linked to numerous high-profile ransomware incidents globally. The group primarily focuses on financial gain through the encryption and subsequent decryption of victims' data in exchange for cryptocurrency payments. Operating with a structured affiliate model, LockBit has demonstrated significant adaptability and targeting precision across multiple sectors.
Goals & Targeting
LockBit's primary strategic objective is financial gain through the deployment of ransomware. The group targets a wide range of sectors due to their affiliate model, which allows them to focus on high-value victims regardless of industry. Their targeting profile includes entities in healthcare, education, manufacturing, and government, as these often have valuable data or limited defenses. Affiliates are incentivized through a revenue-sharing model, making LockBit's operations both scalable and effective. The group's global reach is facilitated by its decentralized structure and the use of sophisticated tools to avoid detection while maximizing payout potential.
Enhanced Description
LockBit operates one of the most successful ransomware-as-a-service (RaaS) platforms globally. The group leverages an affiliate network to conduct intrusions, allowing developers to maintain infrastructure while affiliates execute attacks. This model has made LockBit responsible for a staggering 44% of all ransomware incidents in 2023, according to some sources. Targeting virtually every sector worldwide, LockBit's campaigns have been characterized by their precision and efficiency. The group employs a range of tactics, techniques, and procedures (TTPs) to achieve its objectives, including the use of custom ransomware variants such as HappyMackerel. Notably, LockBit has demonstrated a strong focus on maximizing profits through high-value targets and leveraging affiliate relationships for global reach.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LockBit's campaigns are marked by their rapid operational tempo and precision targeting. The group has been particularly active in the healthcare, education, and manufacturing sectors, leveraging their affiliate network to maximize geographic and sectoral coverage. Notable past operations include attacks on European hospitals, U.S. educational institutions, and Asian manufacturing firms. LockBit's use of double extortion tactics—encrypting data and threatening to leak it unless a ransom is paid—has further increased its notoriety. The group's ability to adapt to new defenses and exploit zero-day vulnerabilities has contributed to their sustained success in the ransomware landscape.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in LockBit's operational capabilities, targeting strategies, and known TTPs. Available intelligence suggests the group has a robust infrastructure and a proven track record of successful campaigns. However, gaps exist in understanding specific tools used and exact kill chains employed in their operations, which limits the completeness of the analysis.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
13
IOCs
0
Observed Data
0
Tactics