• Formerly known as: ABCD
  • First observed: September 2019
  • Model: Ransomware-as-a-Service (RaaS)
  • Status: Disrupted by Operation Cronos (Feb 2024) and a follow-up 2025 breach of its own infrastructure, but not fully eliminated

 

Origin

Threat researchers at SL Cyber, found that LockBit had been in operation for four years since September 2019, initially known as "ABCD," before becoming the most prolific ransomware group. SL Cyber's data notes that LockBit was the most active ransomware group by number of listed victims on its dark web leak site in both 2022 and 2023, claiming over a thousand victims in 2023, including high-profile organizations such as Boeing, the UK Ministry of Defense, and chipmaker TSMC. The FBI noted that by early 2024, LockBit had deployed ransomware against more than 2,000 victims and collected over $120 million in ransom payments.

A joint 2023 cybersecurity advisory from CISA, the FBI, MS-ISAC, and international partners in Australia, Canada, the UK, France, Germany, and New Zealand had already flagged LockBit as the most-deployed ransomware variant worldwide in 2022, tracking roughly 1,700 U.S. attacks and around $91 million in U.S. ransom payments since the group's activity was first observed domestically in January 2020. The advisory also noted that the group accounted for about 18% of reported Australian ransomware incidents in the 2022–2023 period, 22% of Canada's attributed incidents in 2022, 23% of New Zealand's 2022 reports, and 16% of U.S. state and local government ransomware incidents logged by MS-ISAC that same year.

Allan Liska, a ransomware researcher at Recorded Future who has tracked the group for years, summed up why LockBit stood apart from its rivals even before its takedown. Liska noted that LockBit had been the most prolific ransomware strain in recent years in part because its developers offered it to any cybercriminal. LockBit's developers built and maintained the malware and negotiation infrastructure, then rented it out to a network of independent "affiliates" who carried out the actual break-ins in exchange for a majority cut of any ransom collected.

The CISA advisory provides information on how LockBit made itself the affiliate program of choice. Unlike most RaaS operations, which pay themselves first and disburse affiliates' cuts afterward, LockBit lets affiliates collect ransom payments directly before sending a share back to the group. The group also used publicity as a recruiting tool, running campaigns like paying people to get LockBit tattoos and offering a $1 million bounty for anyone who could unmask the real-world identity behind the "LockBitSupp" persona. On the technical side, LockBit lowered the bar to entry by building a simplified, point-and-click administrative panel, making the ransomware accessible to affiliates without much technical skill.

According to a September 2021 threat briefing by HHS's Healthcare Sector Cybersecurity Coordination Center (HC3), LockBit advertised to prospective affiliates on Russian-language cybercrime forums. Affiliates had to set their own ransom amounts and choose their own payment methods, they kept 80% of whatever they collected, and were required to be experienced penetration testers, the program's marketing discouraged less-skilled applicants. LockBit's affiliate terms also instructed affiliates not to target victims in Commonwealth of Independent States (CIS) countries. Around the same period, BleepingComputer reporting cited in the HC3 briefing noted LockBit had also begun openly recruiting company insiders, offering to pay employees for help breaching their own employers' networks, a tactic separate from its outward-facing affiliate recruitment.

CISA advisory documents that the "ABCD" predecessor first appeared in September 2019, LockBit-branded ransomware surfaced on Russian-language cybercrime forums by January 2020, LockBit 2.0 ("Red") arrived in June 2021 with a built-in data-theft tool called StealBit, a Linux/VMware ESXi-targeting version followed in October 2021, LockBit 3.0 ("Black") emerged in March 2022 sharing code similarities with the BlackMatter and BlackCat strains, and LockBit Green appeared in January 2023 incorporating leaked source code from the Conti ransomware group. By April 2023, LockBit encryptors targeting macOS had even turned up on VirusTotal.

 

The group's public stance

The group's rules supposedly prohibited attacks on hospitals and other critical infrastructure, but in practice, those rules were treated as suggestions. NBC News, covering the group's eventual 2024 takedown, described LockBit as one of the most destructive strains of ransomware in recent history, which cybercriminals used to attack American hospitals and schools. The Record's coverage noted that although the group previously claimed to have rules prohibiting attacks on hospitals, it hit Canada's largest children's hospital during the 2022 Christmas season, as well as multiple healthcare facilities in the U.S.

Healthcare has been a persistent target industry-wide, not just for LockBit, a spokesperson for Canada's Communications Security Establishment noted that more than 400 healthcare organizations in Canada and the United States had experienced a ransomware attack since March 2020, according to Healthcare IT News.

 

The SickKids apology

An example of LockBit's contradictory relationship with its rules came in December 2022, when an affiliate hit the Hospital for Sick Children (SickKids) in Toronto. BleepingComputer reported that the attack, which struck late on December 18, 2022, impacted internal and corporate systems, hospital phone lines, and the website, and caused delays in receiving lab and imaging results and longer patient wait times.

LockBit's operators publicly disavowed the attack and released a free decryption tool, posting a statement on their dark web site that read, "We formally apologize for the attack on sickkids.ca and give back the decryptor for free, the partner who attacked this hospital violated our rules, is blocked and is no longer in our affiliate program." BleepingComputer pointed out that LockBit had a documented history of encrypting hospitals without providing decryptors, including its attack against the Center Hospitalier Sud Francilien in France, where it demanded a $10 million ransom and eventually leaked patient data after the hospital refused to pay.

Cybersecurity researcher Chester Wisniewski of Sophos, quoted by Healthcare IT News, offered a theory for why LockBit bothered to apologize, Wisniewski suggested the purpose of LockBit's apology could be to discourage other affiliates who might see attacking a children's hospital as an overstep, deterring them from defecting to a rival ransomware group. He also cautioned that even a "free" decryptor is no guarantee of recovery, noting that healthcare organizations that use a ransomware group's decryptor recover only about two-thirds of their files on average, based on a Sophos survey of hundreds of organizations.

HHS's Health Sector Cybersecurity Coordination Center later examined LockBit's stated targeting "ethics" directly and found them unreliable. HC3's briefing, cited by Healthcare IT News, noted that while an interviewed LockBit operator claimed the group wouldn't operate in certain countries and had reservations about attacking healthcare, adversaries in practice tend to go after whichever victims are easiest to hit, regardless of any ethics.

 

Tactics

The 2023 CISA/FBI advisory provided details of how LockBit affiliates operate once they've decided on a target. Initial access most often comes through exploiting internet-facing vulnerabilities, abusing exposed remote-desktop services, phishing, or simply using stolen valid credentials. After that, affiliates lean on legitimate, publicly available software repurposed for malicious ends rather than custom-built malware. The advisory notes this reliance on freeware and pen-testing tools is common tradecraft across ransomware groups and it helps affiliates blend in with legitimate administrative activity and avoid detection.

The advisory's authors also published a full set of recommended mitigations tied to the MITRE ATT&CK framework, covering everything from phishing-resistant multifactor authentication and 15-character minimum passwords to offline, immutable backups following a 3-2-1 strategy (three copies of data, on two different media, with one kept off-site).

 

Operation Cronos

By early 2024, law enforcement dedicated a years-long international investigation against Lockbit. In February 2024, that investigation, named Operation Cronos, resulted in one of the largest ransomware takedowns ever conducted.

NBC News covered the operation as it unfolded, reporting that agencies from the United States, United Kingdom, and 12 other countries dismantled LockBit's infrastructure and replaced its dark web site with a list of agency press releases and victim resources. FBI Cyber Division deputy assistant director Brett Leatherman told reporters the operation was "several years in the making," while U.S. Attorney General Merrick Garland described the action in a video statement as "taking away the keys to their criminal operation."

According to the NBC News article, the enforcement action also targeted LockBit's human infrastructure, at least five alleged members of the operation were named or arrested. Two affiliates were arrested in Ukraine and Poland at the request of French law enforcement, per a Europol announcement cited in the piece. The U.S. Justice Department also unsealed indictments against Russian nationals Artur Sungatov and Ivan Kondratyev and tied Russian national Mikhail Matveev, already the subject of a $10 million State Department reward, to the group as well.

Furthermore, TechTarget's healthcare security desk reported that the international task force successfully took control of LockBit's leak site and admin portal, as well as 28 servers, and was able to offer decryption keys to victims.

Law enforcement went further than just seizing infrastructure, the NCA also turned LockBit's own leak site against it, and unmasked the individual believed to be the group's administrator, "LockBitSupp." SL Cyber's investigation timeline noted the scale of the group's affiliate network that Operation Cronos exposed, finding that 194 affiliates had been identified as using LockBit's services up until February of that year, and that the group's ransomware had targeted over 1,000 hospitals and healthcare companies, forcing more than 2,000 victims into negotiations.

 

The comeback

HealthITSecurity's Jill Hughes reported that after just a few days of downtime, LockBit restored its servers and was running once again. NCA's Biggar had anticipated this outcome in his takedown announcement, warning, "LockBit may seek to rebuild their criminal enterprise. However, we know who they are, and how they operate. We are tenacious and we will not stop in our efforts to target this group and anyone associated with them."

Nic Finn, a senior threat intelligence consultant at GuidePoint Security, told HealthITSecurity that LockBit's scale made it well-positioned to weather the disruption, noting that the group had likely retained the most affiliates and was still posting the most victims of any operation. Finn also pointed out how ransomware brands can resurface under new names once law enforcement puts pressure, rebranding, he said, is straightforward for operators like LockBit, who could just as easily reappear under a different name and keep running. He noted that his team observed LockBit posting victims to its new leak site almost immediately after resurfacing, though he suspected many of those listings were previously compromised organizations the group simply hadn't gotten around to posting yet, rather than new victims.

Finn also flagged a healthcare-specific consequence, that is, groups like LockBit tend to escalate toward more disruptive, service-impacting attacks after a law enforcement blow, healthcare organizations need recovery plans built for outages that look at more than just data theft.

In May 2025, LockBit suffered a second blow, this time from unknown hackers. Unknown attackers breached what was left of LockBit's infrastructure and replaced its internal dashboards with a taunting message, then leaked a database containing Bitcoin addresses, negotiation transcripts, and stolen affiliate credentials.

Despite the repeated blows, LockBit's codebase and brand are still around. Technical analysis has found that LockBit remains a cyber threat and has shown resilience despite Operation Cronos, with newer versions like LockBit 5.0 continuing to evolve their techniques, such as loading payloads through DLL reflection.

Related: Why LockBit remains one of the most dangerous ransomware threats

 

FAQs

How do ransomware-as-a-service (RaaS) payment structures work?

Most RaaS operators collect ransom payments centrally and disburse affiliates’ shares afterward, though some models allow affiliates to receive payments directly before remitting a commission to the group.

 

What entry-level requirements or costs do new ransomware affiliates face?

Aspiring affiliates often pay upfront fees in cryptocurrency to join RaaS programs, with pricing tiers based on technical skill, experienced penetration testers gain full access while less-skilled criminals can purchase simplified administrative panels.

 

How do ransomware groups evolve technically after law enforcement disruptions?

Following takedowns, ransomware operations frequently release updated variants incorporating advanced techniques like DLL reflection for payload delivery and maintain active victim postings on their leak sites to signal continued capability.