Skip to content
← All Threat Actors
Cybercrime critical Russia / Eastern Europe

LockBit

Ransomware-as-a-Service (RaaS) — Russian-speaking core · Financial — ransomware extortion

Reports 2
Active Since 2019
Last Reported 4 Jun 2026
Sectors Targeted critical-infrastructure, healthcare, finance, government, legal-professional

Tactics, Techniques & Procedures (TTPs)

  • RaaS affiliate model with high revenue share
  • RDP and VPN brute force for initial access
  • Credential stuffing against unpatched SSL-VPN devices
  • StealBit custom exfiltration tool for double extortion
  • EDR and security tool tampering
  • Fastest-benchmarked encryption speed across ransomware families

Known Targets

NHS-adjacent healthcare providersLaw firms and professional servicesManufacturing and logisticsLocal government bodiesFinancial servicesGlobal enterprises across 120+ countries

Analyst Notes

Operation Cronos (February 2024), led by the UK NCA with FBI and Europol, seized LockBit infrastructure and published decryption keys. Administrator Dmitry Khoroshev was indicted in May 2024. Affiliates rebuilt within weeks. LockBit 3.0 (LockBit Black) remains active into 2026 against UK healthcare providers, professional services firms, local government, and manufacturing. Affiliate activity, not a coordinated campaign -- different actors sharing the encryptor and leak site infrastructure. A demonstration that RaaS economics mean no single law enforcement action is sufficient: the administrator remains in Russia, affiliates are globally distributed and individually replaceable, and the leaked encryptor code can be continuously rebuilt.

Also Known As

LockBit 2.0LockBit 3.0 / LockBit BlackLockBit GreenABCD ransomware (predecessor)