Threat Actor Database
#300

Bitwise Spider

APT

Bitwise Spider, identified as LockBit 3.0, is a Russia-based financially motivated ransomware-as-a-service (RaaS) group that emerged in January 2020. This group is known for its highly efficient and adaptable operations, rapidly evolving through multiple versions like LockBit 2.0 and LockBit Black. It stands apart through its aggressive affiliate recruitment strategies, including contests and bounties for insiders, which has significantly expanded its reach and victim count globally. Bitwise Spider primarily employs a double extortion model, encrypting victim data while simultaneously exfiltrating it and threatening public release to coerce ransom payments. The group has also been observed using triple extortion tactics, adding pressure through DDoS attacks or by targeting victims' customers and partners.

RUFinancial gain209 victimsFirst seen: 2020-01-01Last seen: 2026-06-20

Target Sectors

Real EstateHospitalsAccommodationAir TransportationManufacturingConstructionPublic AdministrationOil & GasEducational ServicesWholesale TradeRestaurantsInternet PublishingSpace & DefenseEnergy & Utilities InsuranceEducational ServicesAerospace Product and Parts ManufacturingMedical Equipment and Supplies ManufacturingLumber and Other Construction Materials Merchant WholesalersLegal ServicesManagement, Scientific, and Technical Consulting ServicesScientific Research and Development ServicesRemediation and Other Waste Management ServicesElementary and Secondary SchoolsColleges, Universities, and Professional SchoolsBusiness Schools and Computer and Management TrainingEducational Support ServicesOutpatient Care CentersOther Ambulatory Health Care ServicesSpectator SportsPromoters of Performing Arts, Sports, and Similar EventsIndependent Artists, Writers, and PerformersOther Amusement and Recreation IndustriesRestaurants and Other Eating PlacesPersonal Care ServicesGrantmaking and Giving ServicesCivic and Social OrganizationsExecutive, Legislative, and Other General Government SupportJustice, Public Order, and Safety ActivitiesTelephone Apparatus ManufacturingSemiconductor and Other Electronic Component ManufacturingMedical Equipment and Supplies ManufacturingNew Car DealersElectronics and Appliance StoresFamily Clothing StoresFreight Transportation ArrangementNewspaper PublishersPeriodical PublishersSoftware PublishersMotion Picture and Video ProductionWired and Wireless Telecommunications CarriersData Processing, Hosting, and Related ServicesAll Other Information ServicesPortfolio ManagementEngineering ServicesComputer Systems Design and Related ServicesManagement Consulting ServicesResearch and Development in the Social Sciences and HumanitiesAdvertising AgenciesEmployment Placement Agencies and Executive Search ServicesNational Security&International AffairsMiningTelecommunicationsTransportation&WarehousingRetailElectrical&Electronical ManufacturingInformation ServicesComputer Design & ServicesBankingOtherFinanceBettingProfessional&Technical ServicesHealthCare & Social AssistanceCryptoCurrency & NFTNational SecurityOffices of Certified Public AccountantsOffices of LawyersComputer Systems Design Services

Related CVEs

CVE-2025-8088CVE-2025-6543CVE-2025-64446CVE-2025-6264CVE-2025-61882CVE-2025-59287CVE-2025-5777CVE-2025-53771CVE-2025-53770CVE-2025-49706CVE-2025-49704CVE-2025-4428CVE-2025-4427CVE-2025-31324CVE-2025-31161CVE-2025-30406CVE-2025-2857CVE-2025-2825CVE-2025-27363CVE-2025-24472

ATT&CK IDs

T1595.002 - Vulnerability ScanningT1036.003 - Rename System UtilitiesT1587.001 - MalwareT1045 - Software PackingT1561.002 - Disk Structure WipeT1059.001 - PowerShellT1140 - Deobfuscate/Decode Files or InformationT1083 - File and Directory DiscoveryT1029 - Scheduled TransferT1048 - Exfiltration Over Alternative ProtocolT1078 - Valid AccountsT1530 - Data from Cloud Storage ObjectT1187 - Forced AuthenticationT1486 - Data Encrypted for ImpactT1049 - System Network Connections DiscoveryT1014 - RootkitT1189 - Drive-by CompromiseT1110 - Brute ForceT1081 - Credentials in FilesT1407 - Download New Code at Runtime