Deep Dive: Lockbit (Ransomware)
Today we are analyzing the Lockbit malware family, which falls under the Ransomware category.
Overview
LockBit is one of the most prolific and devastating Ransomware-as-a-Service (RaaS) operations in the world, active since 2019. The LockBit group operates by recruiting affiliates who breach victim networks, while the core developers maintain the ransomware software and leak site infrastructure. LockBit employs double extortion tactics, stealing sensitive data before encrypting systems and threatening to publish the data if a ransom is not paid. Over the years, it has evolved through multiple major versions, including LockBit 2.0 (Red), LockBit 3.0 (Black), and LockBit-NG-Dev (Green). In early 2024, international law enforcement executed Operation Cronos, significantly disrupting the group's infrastructure.
Known Aliases
Security vendors and researchers may refer to this family by several different names, including:
LockBit 2.0LockBit 3.0LockBit Black
MITRE ATT&CK Techniques
This family has been observed utilizing the following techniques:
- T1486: View on MITRE
- T1048: View on MITRE
- T1490: View on MITRE
- T1112: View on MITRE
Frequently Asked Questions
What is LockBit ransomware?
LockBit is a highly active ransomware strain operated under a Ransomware-as-a-Service (RaaS) model. It encrypts victim files and demands a cryptocurrency ransom for the decryption key.
How does the LockBit RaaS model work?
In the RaaS model, the core LockBit developers create the malware and maintain the extortion infrastructure. They recruit affiliates who are responsible for breaching networks and deploying the ransomware. The ransom payments are split between the developers and the affiliates.
What is double extortion?
Double extortion is a tactic where ransomware operators first exfiltrate sensitive data from the victim's network before encrypting the systems. If the victim refuses to pay the ransom to decrypt their files, the attackers threaten to leak the stolen data publicly.
What was Operation Cronos?
Operation Cronos was a major international law enforcement disruption campaign in February 2024 that compromised LockBit's infrastructure, seized their leak sites, and recovered decryption keys to help victims.
This article is part of the Malware Families Catalog. Visit the original page for more details and interactive data! You can also find the full dataset and source code on GitHub, Hugging Face and Kaggle.
Top comments (0)