lockbit
Group profile
LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions.
MITRE ATT&CK TTPs
Initial Access
T1078Valid Accounts
Use of compromised credentials purchased from initial access brokers or obtained through phishing to authenticate to victim environments via RDP or VPN.
T1190Exploit Public-Facing Application
LockBit actors exploit vulnerabilities in public-facing applications including Citrix Bleed (CVE-2023-4966), Fortinet, and other perimeter devices to gain initial access.
T1566Phishing
Spear-phishing emails with malicious attachments or links used to deliver initial stagers.
Execution
T1047Windows Management Instrumentation
WMI used for remote execution of payloads across compromised hosts.
T1053.005Scheduled Task/Job: Scheduled Task
Scheduled tasks created for persistent execution of the LockBit payload and post-compromise tooling.
T1059.001Command and Scripting Interpreter: PowerShell
PowerShell scripts used to deploy ransomware payloads and execute post-exploitation modules.
Persistence
T1547.001Boot or Logon Autostart Execution: Registry Run Keys
Registry Run keys modified to ensure ransomware payload executes on system reboot.
Defense Evasion
T1027Obfuscated Files or Information
LockBit payloads are packed and obfuscated; LockBit 3.0 (Black) uses code from BlackMatter ransomware with added anti-analysis techniques.
T1070.001Indicator Removal: Clear Windows Event Logs
Event logs cleared to remove forensic evidence of the intrusion prior to or after ransomware deployment.
T1562.001Disable or Modify Tools
Windows Defender and other AV/EDR tools disabled via PowerShell commands and Group Policy modifications prior to ransomware deployment.
Credential Access
Discovery
T1046Network Service Discovery
Network scanning tools (Advanced IP Scanner, nmap) used to enumerate hosts, open ports, and services within the victim environment.
T1482Domain Trust Discovery
Active Directory enumeration to map domain trusts and identify targets for lateral movement and domain compromise.
Lateral Movement
T1021.001Remote Services: Remote Desktop Protocol
RDP used extensively for lateral movement across the victim network using stolen credentials.
T1021.002Remote Services: SMB/Windows Admin Shares
PsExec and SMB admin shares leveraged to propagate the ransomware payload laterally.
T1210Exploitation of Remote Services
Exploitation of unpatched internal services to move laterally within the network.
Collection
T1560.001Archive Collected Data: Archive via Utility
7-Zip and WinRAR used to compress stolen data prior to exfiltration as part of double extortion operations.
Exfiltration
T1048Exfiltration Over Alternative Protocol
SFTP and FTP used to transmit stolen data to actor-controlled infrastructure.
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
Rclone and MEGASync used to exfiltrate victim data to cloud storage services ahead of encryption as part of the double extortion model.
Command and Control
Impact
T1486Data Encrypted for Impact
LockBit uses AES-256 for file encryption with RSA-2048 for key protection. LockBit 3.0 uses Salsa20; files are appended with a victim-specific extension. Operates as RaaS with affiliate program.
T1489Service Stop
Database, backup, and security services terminated before encryption to maximize file access and encryption coverage.
T1490Inhibit System Recovery
Shadow copies and backups deleted using vssadmin and wmic commands to prevent recovery without paying the ransom.
Recent victims
| Date | Website / victim | Sector | Country |
|---|---|---|---|
| 2021-08-23 | B Bangkok Airways | Transportation/Logistics | TH |
| 2021-07-30 | A Accenture | Technology | |
| 2021-04-01 | M Merseyrail (Rail network) | Transportation/Logistics | GB |
| 2020-11-30 | K Kopter | Manufacturing | CH |
| 2020-10-21 | P Press Trust of India (PTI) | Technology | IN |

