Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors lockbit3_fs

Description

LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

LockBit3_FS, operating as part of the LockBit 3.0 ransomware family, is a sophisticated cybercriminal group known for its modular encrypted payloads and aggressive global targeting across various sectors. Active since June 2022, they leverage Ransomware-as-a-Service (RaaS) models to maximize financial gains through large-scale ransom demands.

Goals & Targeting

The primary objective of LockBit3_FS is to generate significant financial gains through ransomware operations. They are known to target organizations across all industries, focusing on those with potentially high ransom payment capabilities, regardless of geographical or sectoral boundaries. Their targeting strategy emphasizes maximizing the impact and profitability of each attack.

Enhanced Description

LockBit3_FS operates under the LockBit 3.0 framework, which incorporates elements of the BlackMatter ransomware, making it a significant player in the ransomware landscape. This group typically targets Windows and VMware ESXi environments globally, with no specific sector preference, indicating a broad attack strategy focused on maximizing high-value targets for financial gain. Their use of modular payloads allows them to evade analysis and adapt quickly to defensive measures.

Key Capabilities

  • Modular encrypted payloads
  • Ransomware-as-a-Service (RaaS) platform
  • Targeting Windows and VMware ESXi environments
  • Use of BlackMatter ransomware code
  • Global targeting across all sectors

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Credential Access
Discovery
Lateral Movement

ATT&CK Techniques

T1078.001
T1204.001
T1562.003
T1070.001
T1566.001
T1059.003

Software / Tooling

LockBit 3.0 Ransomware Platform
BlackMatter Code Framework
Custom Malware Tools (e.g., payload delivery mechanisms)
RaaS Infrastructure Management Software

Campaigns & Victims

LockBit3_FS has been involved in multiple high-profile campaigns targeting industries globally, including energy and healthcare sectors. Notable past operations include attacks leveraging VNC-based command-and-control (C2) infrastructure, rapid encryption of targeted systems, and demand for large-scale ransoms. Their operational tempo is consistent, with frequent attacks indicating a mature capability set.

IOC Patterns

  • Ransomware payloads targeting Windows/VMware environments
  • Use of VNC protocol for C2 communication
  • Presence of encrypted files renamed with '.locked' extension
  • Spear-phishing emails with malicious links or attachments

Recommended Actions

  • Monitor network traffic for anomalies related to VNC usage
  • Regularly back up critical systems and store backups offline
  • Enhance endpoint detection capabilities to identify malicious payloads
  • Educate employees on phishing attacks and suspicious email activity
  • Implement strong multi-factor authentication (MFA) for sensitive accounts

Suggested Tags

Ransomware
Financial-Crime
Global-Targeting
Sophisticated-Malware
Encryption-Based-Attack

Confidence Assessment

Confidence in the data on LockBit3_FS is moderate due to their relatively recent emergence and limited公开 reporting. Key gaps include specifics on their exact targeting criteria, detailed attack patterns, and precise infection vectors.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Financial-Crime
Global-Targeting
Sophisticated-Malware
Encryption-Based-Attack

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.