LockBit

Threat Actor

The LockBit ransomware gang first emerged in September 2019. LockBit, like many other ransomware gangs, leases its malicious software to third-party criminal affiliates who then receive a cut of ransoms in exchange for planting the code onto victim networks.

On February 19 2024 authorities took down LockBit's infrastructure, which included 34 servers hosting the data leak website and its mirrors, data stolen from the victims, cryptocurrency addresses, decryption keys, and the affiliate panel. This disruption was part of an international law enforcement operation called Operation Cronos. Five days later, LockBit relaunched with new infrastructure and threatened to focus more of its attacks on the government sector. However, the ransomware gang was never able to return to its previous prominence, with its affiliates moving to other ransomware operations. Over the past year, law enforcement has continued to target LockBit, identifying and charging seven LockBit ransomware members.

Incidents Associated with this Threat

Malware Used by this Threat Actor

No malware identified for this threat actor.