LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.
Objectives
Executive Summary
LockBit3_FS, operating as part of the LockBit 3.0 ransomware family, is a sophisticated cybercriminal group known for its modular encrypted payloads and aggressive global targeting across various sectors. Active since June 2022, they leverage Ransomware-as-a-Service (RaaS) models to maximize financial gains through large-scale ransom demands.
Goals & Targeting
The primary objective of LockBit3_FS is to generate significant financial gains through ransomware operations. They are known to target organizations across all industries, focusing on those with potentially high ransom payment capabilities, regardless of geographical or sectoral boundaries. Their targeting strategy emphasizes maximizing the impact and profitability of each attack.
Enhanced Description
LockBit3_FS operates under the LockBit 3.0 framework, which incorporates elements of the BlackMatter ransomware, making it a significant player in the ransomware landscape. This group typically targets Windows and VMware ESXi environments globally, with no specific sector preference, indicating a broad attack strategy focused on maximizing high-value targets for financial gain. Their use of modular payloads allows them to evade analysis and adapt quickly to defensive measures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LockBit3_FS has been involved in multiple high-profile campaigns targeting industries globally, including energy and healthcare sectors. Notable past operations include attacks leveraging VNC-based command-and-control (C2) infrastructure, rapid encryption of targeted systems, and demand for large-scale ransoms. Their operational tempo is consistent, with frequent attacks indicating a mature capability set.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data on LockBit3_FS is moderate due to their relatively recent emergence and limited公开 reporting. Key gaps include specifics on their exact targeting criteria, detailed attack patterns, and precise infection vectors.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics