Skip to content
Multiple / Non-stateCriminalDisrupted

LockBit

The most prolific ransomware-as-a-service operation ever run — until law enforcement seized its infrastructure and used its own leak site to publish the takedown.

Download profile JSON
Active
2019–present
Motivation
Financial Gain
Aliases
8
Exploited CVEs
5
ATT&CK techniques
10
Cited sources
11

Overview

LockBit was, for several years, the most prolific ransomware operation in the world, responsible for a substantial share of all attacks globally and for over 2,500 victims across roughly 120 countries.

Its success was a matter of business design rather than technical superiority. LockBit ran a professionalised affiliate programme: recruit skilled intruders, give them a reliable encryptor and a working leak site, take a cut, and let them handle access and negotiation. It invested in things affiliates cared about — a fast encryptor, a bug bounty programme, an affiliate control panel, and marketing. LockBit 3.0 shipped with a public bug bounty offering payment for vulnerabilities in its own code.

Operation Cronos changed that. In February 2024 the U.K. National Crime Agency, FBI, and Europol seized the group's infrastructure — and then, pointedly, kept running the leak site, using it to publish details of the takedown, affiliate information, and the fact that the group had retained victim data even after ransoms were paid for its deletion. Investigators recovered over 7,000 decryption keys and offered them to victims free of charge.

In May 2024 authorities identified LockBitSupp — the group's public persona — as Dmitry Yuryevich Khoroshev, a Russian national, and sanctioned and indicted him. The U.S. offered a reward of up to $10 million.

The brand has not meaningfully recovered. Affiliates dispersed to competing operations, and the takedown's real damage was to trust: an affiliate ecosystem depends on believing the operator is competent and will not expose you.

Attribution

Down to the named unit where public evidence supports it.

None — financially motivated ransomware-as-a-service operationRussian-national leadership with a globally distributed affiliate baseConfirmed

In May 2024 the U.S., U.K., and Australia identified LockBitSupp as Dmitry Yuryevich Khoroshev, a Russian national, imposing sanctions and unsealing an indictment. Several affiliates have been separately arrested and charged in multiple countries. The operation was substantially disrupted by Operation Cronos in February 2024, a joint action led by the U.K. National Crime Agency with the FBI, Europol, and partners across ten countries.

Attributing sources

Cross-vendor naming crosswalk

8 designators across 8 organisations.

2 designators are marked partial — the vendor's cluster overlaps this group but is not synonymous with it. Treating a partial correlation as an equivalence is the most common source of attribution error when pivoting between vendor reports.

Microsoft Threat Intelligence

index ↗
  • Storm-0506partialMicrosoft tracks affiliates as separate Storm clusters rather than naming the RaaS brand

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Bitwise Spider

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • UNC2165partialOne affiliate cluster among many deploying LockBit

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • GOLD MYSTIC

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Ambitious Scorpius

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

Recorded Future Insikt Group

index ↗
  • LockBit

Colour prefix encodes attributed origin (RedXxxx = China, BlueXxxx = Russia). TAG-## ('Threat Activity Group') is a provisional designator for clusters pending attribution.

Trend Micro

index ↗
  • Water Selkie

'Earth <name>' for many state-nexus groups; older clusters retain descriptive names such as Pawn Storm.

CISA / NSA / FBI

index ↗
  • LockBit

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

United StatesUnited KingdomFranceGermanyCanadaItalyIndiaBrazilAustralia

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

LockBit 2.0 / 3.0 / Greenransomware

Successive encryptor generations, marketed to affiliates on encryption speed. LockBit Green incorporated leaked Conti source code.

Malpedia ↗
StealBitutility

Purpose-built exfiltration tool provided to affiliates for data theft prior to encryption.

Affiliate control panelframework

Web application for affiliates to generate builds, manage victims, and run negotiations — a genuine product, professionally maintained.

Shared, commodity & living-off-the-land

Cobalt Strikeframework

Standard affiliate post-exploitation tooling for lateral movement.

Legitimate RMM toolsutility

AnyDesk, Atera, and ScreenConnect used by affiliates for persistent access.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by LockBit
CVE-2024-1709KEVransomware10.021 Feb 2024ConnectWise ScreenConnect authentication bypass exploited by affiliates within days of disclosure.SRCHuntress
CVE-2023-4966KEVransomware9.41 Oct 2023CitrixBleed session hijacking used by affiliates for MFA-bypassing access, notably in the Boeing and ICBC Financial Services intrusions.SRCCISA / FBI
CVE-2023-27350KEVransomware9.81 Apr 2023PaperCut print management unauthenticated RCE exploited by affiliates for initial access.SRCMicrosoft Threat Intelligence
CVE-2021-44228KEVransomware10.01 Jan 2022Log4Shell exploited by affiliates against internet-facing Java applications, particularly VMware Horizon.SRCCISA and partners
CVE-2018-13379KEVransomware9.81 Jun 2021FortiOS SSL VPN credentials harvested by affiliates from long-unpatched appliances.SRCCISA and partners

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

5 stages · 10 techniques

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

10 techniques across 5 tactics · 5 with actor-specific notes

Initial Access

3

Command and Control

1

Exfiltration

1

Campaign timeline

  1. Operation Cronos Takedown

    International law enforcement seized LockBit's infrastructure and then continued operating its leak site, using it to publish takedown details, affiliate information, and evidence that the group retained victim data after ransoms were paid for deletion. Over 7,000 decryption keys were recovered and offered to victims.

    ManufacturingHealthcareFinancial ServicesGovernment

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.