LockBit
LockBit is a mature ransomware-as-a-service (RaaS) ecosystem active since at least 2019, evolving from the earlier “ABCD” ransomware into multiple generations (LockBit 1.x, 2.0, 3.0 / Black, Green, Linux/ESXi locker, and most recently 5.0). Public reporting places its first observable activity in September 2019 (ABCD), with LockBit-branded activity seen on Russian-language cybercrime forums from January 2020 onwards.
The operation follows a franchise model: core operators develop and maintain the encryptors, infrastructure and brand, while affiliates handle intrusion, lateral movement and extortion. Across 2022–2024 LockBit consistently ranked among, or as, the most active ransomware family globally, at times responsible for 20–25% of observed attacks.
Typical tradecraft: affiliates obtain initial access via phishing, exploitation of Internet-exposed services (Citrix, VPNs, VMware ESXi, file transfer appliances, etc.), and use of valid credentials. Once inside, they move quickly using tools like Cobalt Strike, PowerShell, PSExec, and RDP, exfiltrate data, then deploy the encryptor. Double extortion (encryption + leak site) is standard; some campaigns add “triple extortion” elements such as DDoS or harassment.
Despite Operation Cronos (February 2024), a major multinational law-enforcement operation that seized core infrastructure, decryption keys and over 200 cryptocurrency accounts and publicly exposed internal data, LockBit did not fully disappear. Activity dipped but affiliates and copycats persisted, and by late 2025 a LockBit 5.0 “return” campaign was being tracked against targets in Europe, the Americas and Asia.
Overall capability: high (mature tooling, long track record, global footprint).
Analytic confidence: high regarding history, structure and TTPs; medium regarding current internal governance and the exact degree of re-centralization after the 2024 takedown.
ATT&CK
MITRE ATT&CK
Research