LockBit Ransomware Operation
LockBit — the most prolific ransomware operation from 2022–2024 with Ransomware-as-a-Service model and hundreds of victims until international disruption in February 2024.
LockBit was the dominant Ransomware-as-a-Service operation (2022–2024), known for world-record ransom demands and fast double encryption, until an international law-enforcement disruption seized its infrastructure in February 2024.
Definition
Ransomware-as-a-Service franchise where affiliates breach and encrypt targets while the core team handles infrastructure and extortion; strong brand discipline and technical polish made it the most prolific operation of its era.
Why It Matters / Profile
- Sponsorship: Unattributed (RaaS business model)
- Active since: 2019
- Aliases: LockBit 2.0, LockBit 3.0, LockBit Black
Current Status
- Review status: published
- Last updated: 2026-08-26
- Evidence: 2 source(s) · 4 technique(s)
- Confidence: 91%
ATT&CK Techniques
Targets
- Broad enterprise
- Manufacturing
- Healthcare
- Government subcontractors
Timeline
- 2019-09-01 — LockBit 1.0 appears
- 2022-06-01 — LockBit 3.0 released
- 2024-02-19 — Operation Cronos disruption; infrastructure seized
Sources
Start Investigation
Move from reading to investigating LockBit Ransomware Operation. The workspace is a structured analysis surface — not a chat — organised as:
- Question — what do you need to know about LockBit Ransomware Operation?
- Evidence — assertions mapped to verifiable references.
- Timeline — events in chronological order.
- Related Entities — CVE, threat actor, campaign, malware links.
- Sources — NVD, CISA KEV, MITRE ATT&CK, vendor advisories.
- Notes — your own observations and working hypotheses.
AI assistance is limited to summarising, explaining, and suggesting related evidence. AI never completes your investigation, modifies entity relationships, or generates facts — all published analysis stays human-reviewed.
Recommended Tools
- IOC LookupSearch OpenTrojan intelligence for indicators attributed to this actor.Look up IOC
Every tool runs passively or locally — inputs are never stored and no target is scanned. Start an investigation on this entity →