Initial Access
3 techniques·derived
Affiliates exploit VPN, Citrix, and Exchange appliances. Purchased or brute-forced RDP and VPN credentials.
The most prolific ransomware-as-a-service operation ever run — until law enforcement seized its infrastructure and used its own leak site to publish the takedown.
LockBit was, for several years, the most prolific ransomware operation in the world, responsible for a substantial share of all attacks globally and for over 2,500 victims across roughly 120 countries.
Its success was a matter of business design rather than technical superiority. LockBit ran a professionalised affiliate programme: recruit skilled intruders, give them a reliable encryptor and a working leak site, take a cut, and let them handle access and negotiation. It invested in things affiliates cared about — a fast encryptor, a bug bounty programme, an affiliate control panel, and marketing. LockBit 3.0 shipped with a public bug bounty offering payment for vulnerabilities in its own code.
Operation Cronos changed that. In February 2024 the U.K. National Crime Agency, FBI, and Europol seized the group's infrastructure — and then, pointedly, kept running the leak site, using it to publish details of the takedown, affiliate information, and the fact that the group had retained victim data even after ransoms were paid for its deletion. Investigators recovered over 7,000 decryption keys and offered them to victims free of charge.
In May 2024 authorities identified LockBitSupp — the group's public persona — as Dmitry Yuryevich Khoroshev, a Russian national, and sanctioned and indicted him. The U.S. offered a reward of up to $10 million.
The brand has not meaningfully recovered. Affiliates dispersed to competing operations, and the takedown's real damage was to trust: an affiliate ecosystem depends on believing the operator is competent and will not expose you.
Down to the named unit where public evidence supports it.
In May 2024 the U.S., U.K., and Australia identified LockBitSupp as Dmitry Yuryevich Khoroshev, a Russian national, imposing sanctions and unsealing an indictment. Several affiliates have been separately arrested and charged in multiple countries. The operation was substantially disrupted by Operation Cronos in February 2024, a joint action led by the U.K. National Crime Agency with the FBI, Europol, and partners across ten countries.
Attributing sources
8 designators across 8 organisations.
2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.
'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Successive encryptor generations, marketed to affiliates on encryption speed. LockBit Green incorporated leaked Conti source code.
Malpedia ↗Purpose-built exfiltration tool provided to affiliates for data theft prior to encryption.
Web application for affiliates to generate builds, manage victims, and run negotiations — a genuine product, professionally maintained.
Shared, commodity & living-off-the-land
Standard affiliate post-exploitation tooling for lateral movement.
AnyDesk, Atera, and ScreenConnect used by affiliates for persistent access.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by LockBit | ||
|---|---|---|---|---|
| CVE-2024-1709KEVransomware | 10.0 | ConnectWise ScreenConnectConnectWise | 21 Feb 2024 | ConnectWise ScreenConnect authentication bypass exploited by affiliates within days of disclosure.SRCHuntress ↗ |
| CVE-2023-4966KEVransomware | 9.4 | Citrix NetScalerCitrix | 1 Oct 2023 | CitrixBleed session hijacking used by affiliates for MFA-bypassing access, notably in the Boeing and ICBC Financial Services intrusions.SRCCISA / FBI ↗ |
| CVE-2023-27350KEVransomware | 9.8 | PaperCut MF / NGPaperCut | 1 Apr 2023 | PaperCut print management unauthenticated RCE exploited by affiliates for initial access.SRCMicrosoft Threat Intelligence ↗ |
| CVE-2021-44228KEVransomware | 10.0 | Apache Log4j2Apache | 1 Jan 2022 | Log4Shell exploited by affiliates against internet-facing Java applications, particularly VMware Horizon.SRCCISA and partners ↗ |
| CVE-2018-13379KEVransomware | 9.8 | FortiOS SSL VPNFortinet | 1 Jun 2021 | FortiOS SSL VPN credentials harvested by affiliates from long-unpatched appliances.SRCCISA and partners ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
3 techniques·derived
Affiliates exploit VPN, Citrix, and Exchange appliances. Purchased or brute-forced RDP and VPN credentials.
1 technique·derived
Disable or Modify Tools.
1 technique·derived
Remote Access Software.
1 technique·derived
StealBit exfiltration prior to encryption for double extortion.
4 techniques·derived
Volume shadow copy deletion and backup destruction before encryption. Terminating database and backup services to ensure files are encryptable.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Affiliates exploit VPN, Citrix, and Exchange appliances
Purchased or brute-forced RDP and VPN credentials
StealBit exfiltration prior to encryption for double extortion
International law enforcement seized LockBit's infrastructure and then continued operating its leak site, using it to publish takedown details, affiliate information, and evidence that the group retained victim data after ransoms were paid for deletion. Over 7,000 decryption keys were recovered and offered to victims.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Overlapping affiliate ecosystem — access brokers and intrusion specialists rotate between RaaS brands.
Competing extortion operations with distinct access models.
FIN7 has been assessed as providing access and tooling into the ransomware affiliate ecosystem.
Curated links to the reports that established what is known about this group.