LOCKBIT 3.0
LOCKBITSUPP
LOCKBIT BLACK
OP CRONOS
Threat IntelligenceRansomwareMarch 8, 202616 min read

LockBit: Threat Intelligence Profile

The most prolific ransomware operation of 2022-2024 with 1,700+ victims and an affiliate bug bounty program, disrupted by Operation Cronos in February 2024.

Scroll

LockBit (also known as LockBit 3.0, LockBit Black, ABCD Ransomware) is the most prolific Ransomware-as-a-Service operation of the 2022-2024 era, responsible for 1,700+ confirmed victims across critical infrastructure, healthcare, and government sectors worldwide. The operation ran an affiliate bug bounty program and was disrupted by the international law enforcement Operation Cronos in February 2024.

Overview & Attribution

LockBit emerged in 2019 as ABCD ransomware before rebranding and rapidly scaling its affiliate program. By 2022, LockBit had become the dominant ransomware operation globally, accounting for roughly 28% of all known ransomware attacks. The group pioneered an affiliate bug bounty program offering $1M+ for vulnerabilities in their infrastructure, and maintained a sophisticated management panel with automated victim negotiation. LockBit 3.0 (LockBit Black) incorporated anti-analysis features borrowed from the BlackMatter codebase.

Threat Assessment

LockBit operated from 2019 to 2024, attributed to Russian-speaking cybercriminals led by the persona LockBitSupp (identified as Dmitry Khoroshev). With 1,700+ victims and an estimated $120M+ in ransom payments collected, LockBit was the single most damaging ransomware operation before Operation Cronos disrupted its infrastructure in February 2024.

Arsenal & Tools

LockBit employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

LockBit affiliates targeted virtually every sector across critical infrastructure, healthcare, financial services, manufacturing, government, education, and legal. The operation maintained geographic restrictions against CIS countries. Affiliates used a wide range of initial access methods including purchased credentials, vulnerable internet-facing services, and phishing.

Operational Pattern

LockBit's affiliate model was highly professionalized. Affiliates received 75-80% of ransom payments, with the core team providing encryptors, infrastructure, and a management panel. The group maintained strict operational security and a public-facing blog that was among the most active data leak sites in the ransomware ecosystem.

MITRE ATT&CK Mapping

TacticTechniqueUsage
ImpactT1486 Data Encrypted for ImpactLockBit 3.0 encryptor with configurable modes and anti-analysis
ImpactT1490 Inhibit System RecoveryAutomated shadow copy deletion and backup destruction
ExecutionT1059 Command and Scripting InterpreterPowerShell, batch, and group policy-based deployment
Lateral MovementT1021 Remote ServicesRDP, SMB, and PSExec for lateral propagation
ExfiltrationT1048 Exfiltration Over Alternative ProtocolStealBit automated exfiltration tool
Defense EvasionT1562 Impair DefensesEDR/AV termination via driver exploits and safe mode boot

Notable Campaigns

LockBit has been linked to multiple significant campaigns:

Detection & Defense

Defend Against LockBit

Mjolnir Security provides specialized capabilities to detect and respond to LockBit operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • Threat Hunting Proactive hunting for LockBit TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of LockBit campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: March 8, 2026