LockBit
Aliases: ABCD ransomware
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-22 04:04:50
- Profile updated
- 2026-07-07 12:47:20
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications retail-and-hospitality education-and-nonprofits government-and-public-sector
Context
LockBit operators tend to be very indiscriminate and opportunistic in their targeting. Actors behind this attack will use a variety of methods to gain initial access, up to and including basic methods such as brute force. After gaining initial access the actor follows a fairly typical escalation, lateral movement and ransomware execution playbook. LockBit operators tend to have a very brief dwell time, executing the final ransomware payload as quickly as they are able to. LockBit ransomware has the built-in lateral movement features; given adequate permissions throughout the targeted environment.
Detection coverage
- 11 YARA rules
Used by threat actors
- BITWISE SPIDER (threat-actor)
- LockBit Affiliate Citrix Bleed Exploits (campaign)
Detection rules
- RUSSIANPANDA_Win_Ransom_Lockbit5 (yara-rule)
- CRAIU_Crime_Lockbit3_Ransomware (yara-rule)
- SIGNATURE_BASE_MAL_SUSP_RANSOM_Lockbit_Ransomnote_Feb24 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Lockbit_Indicators_Feb24 (yara-rule)
- SIGNATURE_BASE_APT_RANSOM_Lockbit_Forensicartifacts_Nov23 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_LNX_Macos_Lockbit_Apr23_1 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Lockbit_Apr23_1 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Lockbit_Locker_LOG_Apr23_1 (yara-rule)
- SIGNATURE_BASE_MAL_RANSOM_Lockbit_Forensicartifacts_Apr23_1 (yara-rule)
- CAPE_Lockbit (yara-rule)
- MALPEDIA_Win_Lockbit_Auto (yara-rule)
Related threat objects
- Lockbit3 (malware)
Reports & references
- CrowdStrike — Double Trouble Ransomware Data Leak Extortion Part 1 (report)
- analyst1.com — Ransom Mafia Analysis Of The World%E2%80%99S First Ransomware Cartel (report)
- CrowdStrike — Report2021Gtr (report)
- analyst1.com — Ransom Mafia Analysis Of The Worlds First Ransomware Cartel (report)
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- sentinelone.com — Lockbit Ransomware Side Loads Cobalt Strike Beacon With Legitimate Vmware Utility (report)
- CrowdStrike — Better Together Global Attitude Survey Takeaways 2021 (report)
- socradar.io — Lockbit 3 Another Upgrade To Worlds Most Active Ransomware (report)
- security.packt.com — Understanding Lockbit (report)
- Trend Micro — Ransomware Spotlight Lockbit (report)
- blogs.vmware.com — Esxi Targeting Ransomware The Threats That Are After Your Virtual Machines Part 1 (report)
- CrowdStrike — Big Game Hunting On The Rise Again According To Ecrime Index (report)
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- ke-la.com — Zooming Into Darknet Threats Targeting Jp Orgs Kela (report)
- news.sophos.com — The Ransomware Threat Intelligence Center (report)
- Broadcom/Symantec — The Ransomware Threat September 2021 (report)
- therecord.media — An Interview With Blackmatter A New Ransomware Group Thats Learning From The Mistakes Of Darkside And Revil (report)
- bleepingcomputer.com — Popular Russian Hacking Forum Xss Bans All Ransomware Topics (report)
- coveware.com — Ransomware Attack Vectors Shift As New Software Vulnerability Exploits Abound (report)
- cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
- Microsoft — Ransomware Groups Continue To Target Healthcare Critical Services Heres How To Reduce Risk (report)
- recordedfuture.com — Blackmatter Ransomware Successor Darkside Revil (report)
- splunk.com — Gone In 52 Seconds And 42 Minutes A Comparative Analysis Of Ransomware Encryption Speed (report)
- splunk.com — An Empirically Comparative Analysis Of Ransomware Binaries (report)
- ESET — Eset Threat Report Q22020 (report)