LockBit 3.0
MITRE ATT&CK: S1202 View on attack.mitre.org
Aliases: LockBit Black, LockBit 3.0
- First seen
- 2022-06-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:46:49
Targeted industries: financial-services healthcare-and-pharmaceutical energy-and-utilities manufacturing government-and-public-sector technology-and-telecommunications
Context
LockBit 3.0 is an evolution of the LockBit Ransomware-as-a-Service (RaaS) offering with similarities to BlackMatter and BlackCat ransomware. LockBit 3.0 has been in use since at least June 2022 and features enhanced defense evasion and exfiltration tactics, robust encryption methods for Windows and VMware ESXi systems, and a more refined RaaS structure over its predecessors such as LockBit 2.0.
Detection coverage
- 4 YARA rules
- 802 Sigma rules
Malware & tools used
- Deobfuscate/Decode Files or Information (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Group Policy Modification (attack-pattern)
- PowerShell (attack-pattern)
- Modify Registry (attack-pattern)
- Mutual Exclusion (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Software Packing (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Service Execution (attack-pattern)
- Web Protocols (attack-pattern)
- Native API (attack-pattern)
- Execution Guardrails (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- File Deletion (attack-pattern)
- CMSTP (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- File and Directory Discovery (attack-pattern)
- System Information Discovery (attack-pattern)
- Network Share Discovery (attack-pattern)
- Standard Encoding (attack-pattern)
- Debugger Evasion (attack-pattern)
- Service Stop (attack-pattern)
Detection rules
- SIGNATURE_BASE_MAL_Backdoor_DLL_Nov23_1 (yara-rule)
- SIGNATURE_BASE_MAL_Trojan_DLL_Nov23 (yara-rule)
- SIGNATURE_BASE_MAL_DLL_Stealer_Nov23 (yara-rule)
- SIGNATURE_BASE_MAL_Python_Backdoor_Script_Nov23 (yara-rule)
Reports & references
- sentinelone.com — Lockbit 3 0 Update Unpicking The Ransomwares Latest Anti Analysis And Evasion Techniques (report)
- CISA — Aa23 165A Understanding Ta Lockbit 0 (report)
- MITRE ATT&CK — S1202 (report)
- CISA — Aa23 075A Stop Ransomware Lockbit (report)
- incibe.es — Lockbit Response And Recovery Actions (report)