Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Dark Web Profile: LockBit Ransomware
Apr 27, 2023
16 Mins Read
Sep 30, 2026
Moon
Summarize with:

Dark Web Profile: LockBit Ransomware

LockBit is a long-running Ransomware-as-a-Service (RaaS) operation that has survived repeated malware upgrades, affiliate turnover, infrastructure exposure, and major law-enforcement disruption. First observed in 2019, the ransomware has evolved through several generations, from the early ABCD strain to LockBit 2.0, LockBit 3.0, LockBit 4.0, and the current LockBit 5.0 generation.

LockBit remains active in 2026. Its latest version extends the operation’s established double extortion model across Windows, Linux, and ESXi environments while introducing additional defense evasion and anti-analysis functionality.

Who Is LockBit?

LockBit was first observed in September 2019 as ABCD ransomware, named after the extension used by its early encryptor. By early 2020, the operation had adopted the LockBit name and developed into an affiliate-driven RaaS model.

Under this structure, LockBit’s core operators maintain the ransomware, affiliate infrastructure, management panels, leak infrastructure, and other supporting services. Affiliates gain access to target networks, perform post-compromise activity, steal information, deploy the ransomware, and conduct extortion. This division means LockBit incidents can differ considerably in their initial access vectors and post exploitation techniques because individual affiliates do not necessarily follow a single intrusion playbook.

Before the major disruption of its operation in 2024, authorities attributed more than 2,500 victims across at least 120 countries to LockBit and reported at least $500 million in ransom payments, alongside billions of dollars in broader losses associated with disruption, incident response, and recovery.

Threat actor card of LockBit

Threat actor card of LockBit

How Did LockBit Evolve?

LockBit’s longevity is closely connected to its ability to repeatedly change both its ransomware and its operating model.

LockBit 2.0

The first major transformation came with LockBit 2.0 in 2021. This generation introduced StealBit, a dedicated data exfiltration component that supported LockBit’s shift toward double extortion. Linux and ESXi-focused functionality also emerged during this period, expanding the operation beyond traditional Windows endpoints.

LockBit 3.0 (LockBit Black)

LockBit 3.0, also known as LockBit Black, emerged in 2022. It introduced a more configurable ransomware design, stronger anti-analysis and evasion functionality, an updated affiliate ecosystem, and a public bug bounty program. LockBit 3.0 could be configured during compilation and further controlled through runtime arguments, giving affiliates options affecting execution, propagation, Safe Mode operation, and other behaviors. Password-protected builds could also require a specific value before the ransomware’s main component would execute, acting as an execution guardrail and making automated analysis more difficult.

LockBit 3.0 Builder Leaked

The LockBit 3.0 ecosystem expanded beyond the group’s own affiliates in September 2022, when its ransomware builder was leaked. The leak allowed actors outside the official LockBit affiliate program to generate customized LockBit 3.0 payloads, complicating attribution because the presence of LockBit malware no longer necessarily meant an intrusion was conducted by an official affiliate.

LockBit Green

Further experimentation followed. LockBit Green appeared in January 2023, incorporating source code originating from another ransomware family. During the same period, test encryptors were discovered for macOS, FreeBSD, ARM, MIPS, SPARC, and other architectures. Some of those experimental builds were incomplete and were not considered ready for reliable operational deployment, but they demonstrated that LockBit’s interest in cross-platform ransomware predated version 5.0.

Operation Cronos: Authorities Disrupt LockBit Ransomware

The operation suffered its biggest disruption in February 2024 during Operation Cronos. International authorities compromised LockBit’s primary platform and other infrastructure, seized dozens of servers, obtained information on affiliates and administrators, and took control of its data leak site. Additional arrests, infrastructure seizures, sanctions, and disclosures followed during 2024.

The disruption also revealed that another generation of LockBit was being developed. LockBit 4.0 was under development at the time of Operation Cronos and was eventually released in early 2025. Its operational footprint was relatively limited before the operation moved to another major revision.

Timeline of LockBit’s evolution, from ABCD to LockBit 5.0

Timeline of LockBit’s evolution, from ABCD to LockBit 5.0

LockBit 5.0 – What’s Known About the Latest LockBit Variant?

In September 2025, LockBit announced LockBit 5.0, presenting it as a renewed version of both the ransomware and affiliate operation. SOCRadar previously examined the launch and the group’s effort to reestablish its presence in its LockBit 5.0 analysis.

Initially, there were legitimate questions about whether the announcement represented a meaningful return or primarily an attempt to restore the LockBit brand following the damage caused by Operation Cronos.

By 2026, functional LockBit 5.0 builds had been analyzed across Windows, Linux, and ESXi, providing stronger evidence that the new version represented an operational ransomware generation rather than only a rebranding exercise. The Windows variant contains the heaviest concentration of defense evasion and anti-analysis capabilities, while the Linux and ESXi versions share much of the same underlying ransomware framework.

Login panel of LockBit 5.0

Login panel of LockBit 5.0

Leak site activity has also demonstrated a sustained comeback. SOCRadar observed 163 claimed victims during Q1 2026, compared with 79 during Q4 2025.

LockBit also participated in public discussions about cooperation with other prominent ransomware operations following the launch of version 5.0. However, no unified leak site or clearly demonstrated pattern of jointly executed attacks has established those groups as one integrated ransomware organization. The current LockBit operation is therefore better analyzed as its own RaaS ecosystem.

What Are LockBit’s Targets?

LockBit has historically followed a broad, affiliate-driven targeting model rather than limiting its attacks to specific industries or regions. Its victims have ranged from small and medium-sized organizations to large enterprises and public institutions, with target selection often influenced by available access, expected ransom value, and the sensitivity of accessible data.

The latest LockBit 5.0 victim data provides a clearer picture of the operation’s current targeting patterns.

Professional Services (17.03%) and Manufacturing (16.76%) account for the largest shares of observed claims, followed by Technology (12.97%) and Healthcare (9.19%). The distribution spans numerous other industries, reflecting the operation’s continued preference for diverse, potentially profitable targets rather than a narrow sectoral focus.

Top 10 industries targeted by LockBit 5.0

Top 10 industries targeted by LockBit 5.0

Geographically, the United States leads with 17.84% of LockBit 5.0 victim listings, followed by Brazil (8.11%), Italy (7.84%), and Germany (7.03%). While North America and Europe remain prominent, the broader distribution demonstrates LockBit’s continued reach across Latin America, Asia, and other regions.

Top 10 countries targeted by LockBit 5.0

Top 10 countries targeted by LockBit 5.0

LockBit 5.0’s affiliate rules also reflect a relatively permissive targeting model, allowing attacks against private businesses, healthcare organizations, and critical infrastructure. Nevertheless, the operation has historically maintained geographic restrictions for certain regions, particularly parts of the post-Soviet area, with malware variants incorporating system language and environmental checks.

What Are LockBit’s Techniques?

LockBit’s RaaS structure results in significant variation between incidents. Initial access and post-compromise activity are often performed by affiliates using their preferred tools and methods, while LockBit’s ransomware and extortion infrastructure provide the common layer connecting the attacks.

Initial Access and Exploitation

LockBit affiliates have historically gained entry through valid or stolen credentials, exposed remote access services, phishing, credential attacks, initial access brokers (IABs), and exploitation of internet-facing vulnerabilities.

Compromised credentials are particularly useful because they may allow an affiliate to enter through an externally accessible service without immediately introducing obvious malicious files. Where remote services are exposed directly to the internet, weak credentials or insufficient authentication controls can provide another access path.

LockBit affiliates have also repeatedly exploited vulnerabilities in public-facing systems. Historically associated examples include:

  • CVE-2018-13379
  • CVE-2019-0708
  • CVE-2020-1472
  • CVE-2021-22986
  • CVE-2021-44228
  • CVE-2023-0669
  • CVE-2023-27350
  • CVE-2023-4966

This is not an exhaustive list and should not be treated as a fixed LockBit vulnerability set. The affiliate model means exploited vulnerabilities can change according to available access and newly exposed systems.

Configurable Execution and Anti-Analysis

LockBit 3.0 significantly expanded the ransomware’s configurable behavior.

Affiliates could modify behavior at compile time and execution time, including options related to propagation and Safe Mode. Certain builds required a password or cryptographic value before the protected ransomware component could be decrypted and executed. This reduced the usefulness of samples obtained by defenders without the corresponding execution information.

LockBit 3.0 could also use environmental checks, system language information, mutexes, packing and runtime decryption to complicate analysis. Its leaked builder further increased variation because customized ransomware samples could be produced outside the official affiliate program.

LockBit 5.0 continues this emphasis on anti-analysis while adding more aggressive defense-evasion behavior in its Windows implementation.

Discovery, Credential Access, and Lateral Movement

Once inside an environment, LockBit affiliates have been observed collecting information about systems, network services, Active Directory relationships, remote access paths, and available storage.

Credential dumping and password recovery can provide additional accounts for privilege escalation and lateral movement. Compromised local or administrative accounts may then be used to access other systems.

LockBit affiliates have historically relied on RDP, SMB administrative shares, remote service execution, Group Policy, remote administration utilities, and tunneling to move through victim environments. Where domain-level privileges are obtained, Group Policy can provide an efficient method of deploying ransomware or other payloads to large numbers of endpoints.

The group’s affiliates have also used legitimate administration, scanning, credential recovery, file-transfer, package management, tunneling, and remote access utilities during intrusions. Because these tools can also serve legitimate purposes, defenders should focus on context, execution location, account behavior, and unusual combinations of activity rather than detecting a product name alone. The old profile contained an extensive inventory of these utilities; the underlying behaviors remain more useful than maintaining a static product list.

Data Collection and Double Extortion

LockBit developed from a primarily encryption-focused ransomware operation into a mature double extortion model, where sensitive information is stolen before systems are encrypted.

LockBit 2.0 introduced StealBit, a dedicated exfiltration utility. Affiliates have also used archive creation, cloud storage services, web-based file transfer channels, FTP/SFTP-style transfer mechanisms, and other methods to move stolen data outside compromised environments.

The stolen data provides leverage even when an organization can successfully restore its systems from backups. LockBit can threaten to publish sensitive information through its data leak site (DLS) unless a payment is made.

The leak infrastructure has also evolved. Following exposure and repeated law enforcement disruption of fixed leak sites, LockBit 5.0 activity in 2026 included the use of victim-specific domains and private torrent-based distribution in some cases. This creates a more fragmented publication model than relying exclusively on a small number of static Tor services.

Encryption and Recovery Disruption

LockBit ransomware has consistently emphasized rapid encryption and interference with recovery.

LockBit 3.0 could stop processes and services, delete Volume Shadow Copies, remove logs, empty the recycle bin, change system wallpaper and icons, and encrypt data across Windows, Linux, and virtualized environments.

LockBit 5.0 expands those capabilities further.

What Are LockBit 5.0’s Key Capabilities?

Analysis of the current generation has identified several notable behaviors:

  • Cross-platform ransomware: Dedicated builds target Windows, Linux, and ESXi environments.
  • Multithreaded encryption: Encryption work is distributed according to available processor resources, improving speed on powerful systems.
  • XChaCha20 and Curve25519: Analyzed 5.0 builds use XChaCha20 for file encryption together with Curve25519-based asymmetric key handling.
  • Random file extensions: Each encrypted file receives a randomly generated 16-character extension rather than one predictable LockBit extension.
  • Process hollowing: The Windows variant can execute its ransomware payload inside a legitimate process.
  • ETW interference: LockBit 5.0 can modify Event Tracing for Windows functionality to reduce security telemetry.
  • Log clearing: Event logs can be cleared to reduce forensic visibility.
  • Security and recovery disruption: Backup, database, security, and other services may be terminated before or during encryption.
  • Shadow-copy deletion: Recovery data can be removed directly to inhibit restoration.
  • Virtual-machine targeting: The ESXi variant can enumerate and terminate running virtual machines before encrypting their files.
  • Free-space wiping: Analyzed variants support wiping unused disk space after encryption, further complicating forensic recovery.

The Linux and ESXi builds share much of the same execution and encryption framework, while the Windows build contains the most extensive anti-analysis and defense-evasion features. The ESXi version additionally contains virtualization-specific logic, including identifying registered virtual machines and stopping them so their files can be encrypted without being locked by the hypervisor.

These capabilities show a progression that began well before LockBit 5.0. Experimental multi-platform builds discovered in 2023 demonstrated the group’s interest in widening its target surface, while version 5.0 turned that direction into a more mature operational framework.

What Are the Mitigation Tactics Against LockBit?

Because LockBit affiliates can use different intrusion paths, organizations should focus on reducing opportunities across the full ransomware attack chain rather than looking for one LockBit-specific control.

Reduce Initial Access Opportunities

Organizations should minimize exposed remote-access services and disable services that are not operationally necessary. Internet-accessible administrative interfaces should not be left directly exposed where avoidable.

Multi-factor authentication should be required for remote access, administrative accounts, and externally accessible services, with phishing resistant methods preferred for privileged users.

Authentication monitoring should identify brute force attempts, password spraying, unusual login locations, repeated authentication failures, and abnormal privileged account activity.

Internet-facing assets should also be inventoried continuously and patched according to exposure and exploitation risk. LockBit affiliates have historically exploited both newly disclosed and older vulnerabilities, meaning delayed patching can leave useful access paths available long after fixes are released.

Restrict Privileges and Lateral Movement

Organizations should separate privileged accounts from standard user accounts, minimize reusable local administrator credentials, and enforce least privilege.

Network segmentation should restrict unnecessary communication between endpoints and isolate critical systems such as domain infrastructure, backup servers, virtualization management, and sensitive data repositories.

Security teams should monitor unexpected RDP activity, administrative share access, remote service creation, Group Policy changes, privilege escalation, credential dumping, and unusual remote management sessions.

Detect Pre-Encryption Behavior

Many ransomware operations reveal themselves through post-compromise behavior before mass encryption begins.

For LockBit 5.0, high value detection opportunities include process injection or hollowing, ETW modification, event log clearing, mass termination of services, deletion of Volume Shadow Copies, interruption of backup systems, and sudden large scale file modification.

Unexpected shutdown of multiple virtual machines should also be treated as a high priority event, especially when associated with unusual privileged sessions or unfamiliar command execution on virtualization hosts.

Because LockBit 5.0 uses randomly generated encrypted-file extensions, defenses should not rely primarily on extension-based detection.

Protect Backup and Virtualization Infrastructure

Backups should be isolated from normal production credentials, regularly tested, encrypted where appropriate, and stored through offline or immutable mechanisms when possible.

Backup administration should use dedicated accounts and authentication paths. LockBit specifically targets backup and recovery functions, making a backup system that shares the same credentials or trust relationships as compromised production infrastructure significantly less resilient.

Virtualization infrastructure deserves similar protection. Administrative interfaces should be tightly restricted, privileged activity logged, and mass virtual-machine shutdown or snapshot deletion monitored closely.

Monitor Data Theft and Extortion

Recovery planning should account for data theft as well as encryption.

Security teams should monitor large archive creation, unexpected outbound transfers, access to sensitive repositories, unusual use of file-transfer mechanisms, and atypical data movement from servers holding valuable information.

External monitoring is also relevant because the first public sign of some incidents may be a ransomware listing or publication threat. However, DLS claims should be validated against endpoint, network, identity, cloud, and DLP telemetry rather than automatically treated as proof of a confirmed breach.

SOCRadar’s Attack Surface Management can help identify exposed assets and vulnerabilities that may provide ransomware affiliates with an initial foothold, while Dark Web Monitoring can provide visibility into ransomware claims, leak sites, and underground activity. Vulnerability Intelligence can further help teams prioritize weaknesses according to exploitation and threat context.

SOCRadar’s Dark Web Monitoring

SOCRadar’s Dark Web Monitoring

What Are the MITRE ATT&CK TTPs of LockBit?

LockBit’s affiliate model means no single intrusion will contain every technique below. The mappings combine recurring LockBit affiliate behavior, established techniques from earlier ransomware generations, and relevant behavior observed in LockBit 5.0.

Tactic ID Technique
Initial Access T1078 Valid Accounts
T1133 External Remote Services
T1189 Drive-by Compromise
T1190 Exploit Public-Facing Application
T1566 Phishing
Execution T1072 Software Deployment Tools
T1569.002 System Services: Service Execution
Persistence / Privilege Escalation T1547 Boot or Logon Autostart Execution
Privilege Escalation T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control
Defense Evasion T1027 Obfuscated Files or Information
T1480.001 Execution Guardrails: Environmental Keying
T1480.002 Execution Guardrails: Mutual Exclusion
T1055.012 Process Injection: Process Hollowing
T1070.001 Indicator Removal: Clear Windows Event Logs
T1562.001 Impair Defenses: Disable or Modify Tools
T1688 Safe Mode Boot
Credential Access T1003.001 OS Credential Dumping: LSASS Memory
Discovery T1046 Network Service Discovery
T1082 System Information Discovery
T1614.001 System Location Discovery: System Language Discovery
T1482 Domain Trust Discovery
Lateral Movement T1021.001 Remote Services: Remote Desktop Protocol
T1021.002 Remote Services: SMB/Windows Admin Shares
Privilege Escalation / Defense Evasion T1484.001 Domain or Tenant Policy Modification: Group Policy Modification
Command and Control T1219 Remote Access Software
T1572 Protocol Tunneling
Collection T1560.001 Archive Collected Data: Archive via Utility
Exfiltration T1567 Exfiltration Over Web Service
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage
Impact T1485 Data Destruction
T1486 Data Encrypted for Impact
T1489 Service Stop
T1490 Inhibit System Recovery
T1491.001 Defacement: Internal Defacement

Current ATT&CK documentation also identifies several LockBit 3.0-specific procedure examples, including UAC bypass, Group Policy propagation, password-based execution guardrails, mutex creation, runtime payload decryption, Safe Mode execution, and Volume Shadow Copy deletion.

What Are the Indicators of Compromise (IOCs) for LockBit?

LockBit IOCs vary considerably between versions, affiliates, individual builds, and infrastructure changes. The IP addresses and malware hashes included in the previous LockBit 3.0 profile remain useful for historical hunting, but they should not be treated as a current LockBit detection set.

The following indicators are associated with analyzed LockBit 5.0 samples and infrastructure.

LockBit 5.0 Malware Hashes

Type Platform Indicator
SHA-256 Windows x64 7ea5afbc166c4e23498aa9747be81ceaf8dad90b8daa07a6e4644dc7c2277b82
SHA-256 Windows x64 180e93a091f8ab584a827da92c560c78f468c45f2539f73ab2deb308fb837b38
SHA-256 Linux x64 4dc06ecee904b9165fa699b026045c1b6408cc7061df3d2a7bc2b7b4f0879f4d
SHA-256 Linux x64 98d8c7870c8e99ca6c8c25bb9ef79f71c25912fbb65698a9a6f22709b8ad34b6
SHA-256 ESXi x64 90b06f07eb75045ea3d4ba6577afc9b58078eafeb2cdd417e2a88d7ccf0c0273

These hashes correspond to specific analyzed samples and should not be expected to identify every LockBit 5.0 build.

LockBit 5.0 Infrastructure Indicators

Type Indicator Context
IP 205.185.116[.]233 Infrastructure publicly linked to LockBit 5.0 in December 2025.
Domain karma0[.]xyz Domain observed alongside the exposed LockBit 5.0 infrastructure.
Port 3389/TCP Remote desktop access was exposed on the identified server.

The identified server went offline shortly after its exposure, so these values should now be treated primarily as historical infrastructure indicators, not assumptions about LockBit’s current hosting.

Additional Behavioral Indicators

Static IOCs alone are particularly limited against LockBit because ransomware samples and infrastructure can change quickly. Defenders should also look for combinations of behaviors such as:

  • Random 16-character extensions suddenly appearing across large numbers of files.
  • High-volume file encryption across endpoints or shared storage.
  • Event-log clearing combined with service termination.
  • ETW modification or unexpected process-hollowing activity.
  • Volume Shadow Copy deletion.
  • Backup or database services being stopped unexpectedly.
  • Unusual enumeration or shutdown of multiple virtual machines.
  • Large archive creation or unexpected outbound data movement before encryption.
  • Ransom-note creation across multiple directories.

SOCRadar’s current LockBit Ransomware Intelligence profile tracks evolving hashes, URLs, IP addresses, hostnames, TTPs, victim claims, and related intelligence as the operation changes.

LockBit’s development from ABCD to LockBit 5.0 shows why ransomware profiles cannot rely on a single generation’s hashes, extensions, or infrastructure. The underlying operation has repeatedly changed its malware, affiliate model, platforms, and public infrastructure while retaining the same core objective: gaining access, stealing valuable data, disrupting systems through encryption, and using both operational impact and exposure threats to pressure victims.