LOCKBIT
RANSOMWARE
DOUBLE EXTORTION
RAAS
Threat IntelligenceRansomwareDecember 26, 202515 min read

LockBit Ransomware: Threat Intelligence Profile

Most prolific RaaS operation before Operation Cronos

Scroll

LockBit Ransomware is a ransomware operation attributed to eCrime (LockBitSupp), active since 2019. Most prolific RaaS operation before Operation Cronos. Key capabilities include: StealBit, LockBit 3.0/Green/Black, Operation Cronos Feb 2024, $110M+ ransoms.

Overview & Operations

Most prolific RaaS operation before Operation Cronos. The group has been active since 2019 and operates as part of the broader ransomware-as-a-service ecosystem. Notable technical characteristics include: StealBit, LockBit 3.0/Green/Black, Operation Cronos Feb 2024, $110M+ ransoms.

Ransomware Threat

LockBit Ransomware employs double extortion tactics — encrypting victim data while simultaneously exfiltrating sensitive information for leverage. Organizations that refuse to pay face public data exposure on the group's leak site.

Tactics, Techniques & Procedures

LockBit operators typically gain initial access through phishing, exploiting public-facing applications (VPN, RDP, Exchange), or purchasing access from initial access brokers (IABs). Post-compromise, they deploy Cobalt Strike or similar C2 frameworks for lateral movement before deploying the ransomware payload.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1190 Exploit Public-Facing AppVPN/RDP/Exchange exploitation
ExecutionT1059.001 PowerShellPost-exploitation scripting
PersistenceT1053.005 Scheduled TaskPersistence mechanism
Defense EvasionT1562.001 Disable Security ToolsEDR/AV tampering
Credential AccessT1003.001 LSASS MemoryCredential dumping
Lateral MovementT1021.002 SMB/Admin SharesNetwork propagation
ExfiltrationT1567 Exfil Over Web ServiceData theft before encryption
ImpactT1486 Data Encrypted for ImpactRansomware deployment

Detection & Defense

Protect Against LockBit Ransomware

Mjolnir Security provides ransomware prevention, detection, and response services against LockBit Ransomware and similar threats.

Ransomware DefenseIncident ResponseThreat HuntingMDR ServicesBackup AssessmentTabletop Exercises
  • Ransomware Readiness Assessment Evaluate your organization's resilience against LockBit and similar ransomware operations with gap analysis and remediation recommendations.
  • Ransomware Incident Response Rapid containment, negotiation support, and forensic investigation when ransomware strikes.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: December 26, 2025