{
  "name": "Adversary Atlas API",
  "version": "1.0.0",
  "description": "Read-only JSON API over the Adversary Atlas threat actor dataset. Statically generated at build time; no authentication, no rate limits.",
  "generated": "2026-07-31T01:06:07.226Z",
  "datasetCurrentAsOf": "2025-09-01",
  "license": "Data compiled from public primary sources; see /methodology/ for sourcing.",
  "actor": {
    "id": "lockbit",
    "slug": "lockbit",
    "name": "LockBit",
    "shortName": "LockBit",
    "country": "Multiple / Non-state",
    "countryCode": "XX",
    "sponsorship": "criminal",
    "status": "disrupted",
    "activeSince": "2019",
    "prominence": 88,
    "tagline": "The most prolific ransomware-as-a-service operation ever run — until law enforcement seized its infrastructure and used its own leak site to publish the takedown.",
    "bio": "LockBit was, for several years, the most prolific ransomware operation in the world, responsible for a substantial share of all attacks globally and for over 2,500 victims across roughly 120 countries.\n\nIts success was a matter of business design rather than technical superiority. LockBit ran a professionalised affiliate programme: recruit skilled intruders, give them a reliable encryptor and a working leak site, take a cut, and let them handle access and negotiation. It invested in things affiliates cared about — a fast encryptor, a bug bounty programme, an affiliate control panel, and marketing. LockBit 3.0 shipped with a public bug bounty offering payment for vulnerabilities in its own code.\n\nOperation Cronos changed that. In February 2024 the U.K. National Crime Agency, FBI, and Europol seized the group's infrastructure — and then, pointedly, kept running the leak site, using it to publish details of the takedown, affiliate information, and the fact that the group had retained victim data even after ransoms were paid for its deletion. Investigators recovered over 7,000 decryption keys and offered them to victims free of charge.\n\nIn May 2024 authorities identified LockBitSupp — the group's public persona — as Dmitry Yuryevich Khoroshev, a Russian national, and sanctioned and indicted him. The U.S. offered a reward of up to $10 million.\n\nThe brand has not meaningfully recovered. Affiliates dispersed to competing operations, and the takedown's real damage was to trust: an affiliate ecosystem depends on believing the operator is competent and will not expose you.",
    "attribution": {
      "sponsor": "None — financially motivated ransomware-as-a-service operation",
      "service": "Russian-national leadership with a globally distributed affiliate base",
      "confidence": "confirmed",
      "summary": "In May 2024 the U.S., U.K., and Australia identified LockBitSupp as Dmitry Yuryevich Khoroshev, a Russian national, imposing sanctions and unsealing an indictment. Several affiliates have been separately arrested and charged in multiple countries. The operation was substantially disrupted by Operation Cronos in February 2024, a joint action led by the U.K. National Crime Agency with the FBI, Europol, and partners across ten countries.",
      "sources": [
        {
          "org": "U.S. Department of Justice",
          "title": "U.S. Charges Russian National with Developing and Operating LockBit Ransomware",
          "url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
          "date": "2024-05-07"
        },
        {
          "org": "Europol / NCA",
          "title": "Law enforcement disrupt world's biggest ransomware operation (Operation Cronos)",
          "url": "https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-disrupt-worlds-biggest-ransomware-operation",
          "date": "2024-02-20"
        },
        {
          "org": "CISA / FBI and international partners",
          "title": "Understanding Ransomware Threat Actors: LockBit (AA23-165A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
          "date": "2023-06-14"
        }
      ]
    },
    "motivations": [
      "financial-gain"
    ],
    "targetSectors": [
      "Manufacturing",
      "Healthcare",
      "Financial Services",
      "Government",
      "Education",
      "Technology",
      "Transportation",
      "Legal",
      "Retail & Hospitality",
      "Critical Infrastructure"
    ],
    "targetCountries": [
      "United States",
      "United Kingdom",
      "France",
      "Germany",
      "Canada",
      "Italy",
      "India",
      "Brazil",
      "Australia"
    ],
    "aliases": [
      {
        "org": "microsoft",
        "name": "Storm-0506",
        "correlation": "partial",
        "note": "Microsoft tracks affiliates as separate Storm clusters rather than naming the RaaS brand"
      },
      {
        "org": "crowdstrike",
        "name": "Bitwise Spider",
        "correlation": "exact"
      },
      {
        "org": "mandiant",
        "name": "UNC2165",
        "correlation": "partial",
        "note": "One affiliate cluster among many deploying LockBit"
      },
      {
        "org": "secureworks",
        "name": "GOLD MYSTIC",
        "correlation": "exact"
      },
      {
        "org": "unit42",
        "name": "Ambitious Scorpius",
        "correlation": "exact"
      },
      {
        "org": "cisa",
        "name": "LockBit",
        "correlation": "exact"
      },
      {
        "org": "trendmicro",
        "name": "Water Selkie",
        "correlation": "exact"
      },
      {
        "org": "recordedfuture",
        "name": "LockBit",
        "correlation": "exact"
      }
    ],
    "tools": [
      {
        "name": "LockBit 2.0 / 3.0 / Green",
        "type": "ransomware",
        "custom": true,
        "description": "Successive encryptor generations, marketed to affiliates on encryption speed. LockBit Green incorporated leaked Conti source code.",
        "malpediaSlug": "win.lockbit"
      },
      {
        "name": "StealBit",
        "type": "utility",
        "custom": true,
        "description": "Purpose-built exfiltration tool provided to affiliates for data theft prior to encryption."
      },
      {
        "name": "Affiliate control panel",
        "type": "framework",
        "custom": true,
        "description": "Web application for affiliates to generate builds, manage victims, and run negotiations — a genuine product, professionally maintained."
      },
      {
        "name": "Cobalt Strike",
        "type": "framework",
        "custom": false,
        "description": "Standard affiliate post-exploitation tooling for lateral movement."
      },
      {
        "name": "Legitimate RMM tools",
        "type": "utility",
        "custom": false,
        "description": "AnyDesk, Atera, and ScreenConnect used by affiliates for persistent access."
      }
    ],
    "techniques": [
      {
        "tCode": "T1190",
        "name": "Exploit Public-Facing Application",
        "tactic": "Initial Access",
        "note": "Affiliates exploit VPN, Citrix, and Exchange appliances"
      },
      {
        "tCode": "T1133",
        "name": "External Remote Services",
        "tactic": "Initial Access",
        "note": "Purchased or brute-forced RDP and VPN credentials"
      },
      {
        "tCode": "T1486",
        "name": "Data Encrypted for Impact",
        "tactic": "Impact"
      },
      {
        "tCode": "T1490",
        "name": "Inhibit System Recovery",
        "tactic": "Impact",
        "note": "Volume shadow copy deletion and backup destruction before encryption"
      },
      {
        "tCode": "T1489",
        "name": "Service Stop",
        "tactic": "Impact",
        "note": "Terminating database and backup services to ensure files are encryptable"
      },
      {
        "tCode": "T1567",
        "name": "Exfiltration Over Web Service",
        "tactic": "Exfiltration",
        "note": "StealBit exfiltration prior to encryption for double extortion"
      },
      {
        "tCode": "T1562.001",
        "name": "Impair Defenses: Disable or Modify Tools",
        "tactic": "Defense Evasion"
      },
      {
        "tCode": "T1078",
        "name": "Valid Accounts",
        "tactic": "Initial Access"
      },
      {
        "tCode": "T1219",
        "name": "Remote Access Software",
        "tactic": "Command and Control"
      },
      {
        "tCode": "T1657",
        "name": "Financial Theft",
        "tactic": "Impact"
      }
    ],
    "cves": [
      {
        "cveId": "CVE-2023-4966",
        "firstExploited": "2023-10-01",
        "usage": "CitrixBleed session hijacking used by affiliates for MFA-bypassing access, notably in the Boeing and ICBC Financial Services intrusions.",
        "source": {
          "org": "CISA / FBI",
          "title": "Threat Actors Exploit CitrixBleed in LockBit 3.0 Ransomware Attacks (AA23-325A)",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a",
          "date": "2023-11-21"
        }
      },
      {
        "cveId": "CVE-2021-44228",
        "firstExploited": "2022-01-01",
        "usage": "Log4Shell exploited by affiliates against internet-facing Java applications, particularly VMware Horizon.",
        "source": {
          "org": "CISA and partners",
          "title": "AA23-165A: Understanding Ransomware Threat Actors: LockBit",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
          "date": "2023-06-14"
        }
      },
      {
        "cveId": "CVE-2023-27350",
        "firstExploited": "2023-04-01",
        "usage": "PaperCut print management unauthenticated RCE exploited by affiliates for initial access.",
        "source": {
          "org": "Microsoft Threat Intelligence",
          "title": "Ransomware operators exploiting PaperCut vulnerabilities",
          "url": "https://www.microsoft.com/en-us/security/blog/",
          "date": "2023-04-26"
        }
      },
      {
        "cveId": "CVE-2018-13379",
        "firstExploited": "2021-06-01",
        "usage": "FortiOS SSL VPN credentials harvested by affiliates from long-unpatched appliances.",
        "source": {
          "org": "CISA and partners",
          "title": "AA23-165A: Understanding Ransomware Threat Actors: LockBit",
          "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
          "date": "2023-06-14"
        }
      },
      {
        "cveId": "CVE-2024-1709",
        "firstExploited": "2024-02-21",
        "usage": "ConnectWise ScreenConnect authentication bypass exploited by affiliates within days of disclosure.",
        "source": {
          "org": "Huntress",
          "title": "ScreenConnect exploitation and ransomware deployment",
          "url": "https://www.huntress.com/blog/a-catastrophe-for-control-understanding-the-screenconnect-authentication-bypass",
          "date": "2024-02-21"
        }
      }
    ],
    "relationships": [
      {
        "relatedActorId": "scattered-spider",
        "type": "operational-overlap",
        "confidence": "moderate",
        "note": "Overlapping affiliate ecosystem — access brokers and intrusion specialists rotate between RaaS brands."
      },
      {
        "relatedActorId": "cl0p",
        "type": "operational-overlap",
        "confidence": "low",
        "note": "Competing extortion operations with distinct access models."
      },
      {
        "relatedActorId": "fin7",
        "type": "supplier",
        "confidence": "moderate",
        "note": "FIN7 has been assessed as providing access and tooling into the ransomware affiliate ecosystem."
      }
    ],
    "reports": [
      {
        "org": "CISA / FBI and partners",
        "title": "AA23-165A: Understanding Ransomware Threat Actors — LockBit",
        "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
        "date": "2023-06-14"
      },
      {
        "org": "UK National Crime Agency",
        "title": "NCA leads international investigation targeting LockBit (Operation Cronos)",
        "url": "https://www.nationalcrimeagency.gov.uk/news/nca-leads-international-investigation-targeting-worlds-most-harmful-ransomware-group",
        "date": "2024-02-20"
      },
      {
        "org": "U.S. Department of Justice",
        "title": "Indictment and sanctions: Dmitry Yuryevich Khoroshev (LockBitSupp)",
        "url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
        "date": "2024-05-07"
      }
    ],
    "campaigns": [
      {
        "id": "operation-cronos",
        "actorId": "lockbit",
        "name": "Operation Cronos Takedown",
        "date": "2024-02-19",
        "significance": "major",
        "targetSectors": [
          "Manufacturing",
          "Healthcare",
          "Financial Services",
          "Government"
        ],
        "targetCountries": [
          "United States",
          "United Kingdom",
          "France",
          "Germany",
          "Canada"
        ],
        "cveIds": [],
        "summary": "International law enforcement seized LockBit's infrastructure and then continued operating its leak site, using it to publish takedown details, affiliate information, and evidence that the group retained victim data after ransoms were paid for deletion. Over 7,000 decryption keys were recovered and offered to victims.",
        "sources": [
          {
            "org": "Europol / NCA",
            "title": "Law enforcement disrupt world's biggest ransomware operation",
            "url": "https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-disrupt-worlds-biggest-ransomware-operation",
            "date": "2024-02-20"
          }
        ]
      }
    ],
    "flag": "🏴",
    "profile": "/apt/lockbit/"
  }
}