Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

All Threat Actors

LockBit

Also known as: LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green, ABCD Ransomware, Water Selkie, LockBit 4.0, LockBit Neo, LockBit 5.0, ChuongDong, LockBit-NG-Dev, SuperBlack

ActiveExpertRussia
0Campaigns
44Techniques
22IOCs
21Tools
0Matches
4Infrastructure
OverviewTechniquesToolsIOCsInfrastructureReferences

Overview

LockBit is a highly resilient ransomware-as-a-service (RaaS) operation that has survived multiple law enforcement disruptions including Operation Cronos (February 2024) and a May 2025 infrastructure breach that exposed affiliate data. The group released LockBit 5.0 in September 2025 with enhanced cross-platform capabilities targeting Windows, Linux, and ESXi environments. Built on .NET Core, the new variant features improved obfuscation, ETW patching, invisible mode encryption, and randomized 16-character file extensions. Despite setbacks, LockBit recorded over 200 victims on its data leak site from December 2025 into early 2026, primarily targeting U.S., India, and Brazil across manufacturing, healthcare, and government sectors.

Motivations

Financial GainExtortion

Target Sectors

HealthcareGovernmentEducationFinancial ServicesManufacturingLegalConstructionTechnologyCritical InfrastructureBanking/Financial Services/Insurance (BFSI)South America RegionVMware ESXi InfrastructureVirtualization PlatformsRetailLegal ServicesTransportationFinanceProfessional ServicesFood ServicesEnergy

Activity Timeline

First Seen

Sep 2019

Last Seen

Jan 2026

Quick Facts

OriginRussia
Sophisticationexpert
StatusActive

MITRE ATT&CK Techniques

(44)

Initial Access

T1190

Exploit Public-Facing Application

Exploit vulnerabilities in internet-facing applications to gain access.

T1133

External Remote Services

Abuse remote services like VPNs or RDP to gain access to the network.

T1078

Valid Accounts

Use legitimate credentials to authenticate and gain access.

Execution

T1059.001

PowerShell

Use PowerShell commands and scripts for execution and automation.

T1059.003

Windows Command Shell

Use cmd.exe to execute commands and batch scripts.

T1047

Windows Management Instrumentation

Use WMI to execute commands and manage systems remotely.

Impact

T1486

Data Encrypted for Impact

Encrypt victim data to disrupt availability, typically for ransom.

T1490

Inhibit System Recovery

Delete backups, shadow copies, or recovery partitions to prevent restoration.

T1489

Service Stop

Stop critical services to disrupt operations or aid in data destruction.

Other

T1562.001

T1562.001

T1070.001

T1070.001

T1567.002

T1567.002

T1574.002

T1574.002

T1218.011

T1218.011

T1027.013

T1027.013

T1204.002

T1204.002

T1135

T1135

T1016

T1016

T1049

T1049

T1033

T1033

T1007

T1007

T1112

T1112

T1543.003

T1543.003

T1106

T1106

T1569.002

T1569.002

T1560.001

T1560.001

T1057

T1057

T1012

T1012

T1588.002

T1588.002

T1562.006

T1562.006

T1480

T1480

T1027.002

T1027.002

Defense Evasion

T1027

Obfuscated Files or Information

Encrypt, encode, or obfuscate payloads and data to evade detection.

T1055

Process Injection

Inject code into running processes to evade defenses and elevate privileges.

T1036

Masquerading

Disguise malicious artifacts by manipulating names or locations to appear legitimate.

T1140

Deobfuscate/Decode Files or Information

Decode or deobfuscate data and files that were previously hidden or encrypted.

Lateral Movement

T1021.001

Remote Desktop Protocol

Use RDP to connect to and control remote systems.

Credential Access

T1003.001

LSASS Memory

Access LSASS process memory to extract credential material.

Exfiltration

T1041

Exfiltration Over C2 Channel

Exfiltrate stolen data over the existing command and control channel.

Discovery

T1083

File and Directory Discovery

Enumerate files and directories to find sensitive data or binaries.

T1018

Remote System Discovery

Discover remote systems on the network for lateral movement targets.

T1082

System Information Discovery

Collect OS version, architecture, hostname, and other system details.

Persistence

T1136

Create Account

Create new accounts to maintain access to victim systems.

Reconnaissance

T1592

Gather Victim Host Information

Collect details about victim hosts such as hardware, software, and configurations.

Tools & Malware

(21)

LockBit Ransomware

malwareMalicious

Core RaaS ransomware supporting Windows, Linux, and VMware ESXi. Known for fast encryption using AES-256 + RSA-2048 and automatic propagation via SMB and Group Policy.

StealBit

malwareMalicious

Custom data exfiltration tool developed by LockBit operators. Rapidly extracts files to attacker infrastructure before encryption for double-extortion leverage.

Cobalt Strike

frameworkLegitimate

Most commonly used post-exploitation framework by LockBit affiliates. Deployed via initial access vectors for reconnaissance, lateral movement, and pre-encryption staging.

Brute Ratel

frameworkLegitimate

Alternative C2 framework used by some LockBit affiliates to evade EDR detections that commonly flag Cobalt Strike. Supports syscall-level evasion.

Mimikatz

frameworkLegitimate

Standard credential harvesting tool for extracting passwords, NTLM hashes, and Kerberos tickets to gain domain admin access before deploying ransomware.

AnyDesk

legitimate toolLegitimate

Deployed widely by affiliates for persistent remote access. Installed on multiple endpoints to maintain access even if C2 beacons are detected and killed.

TeamViewer

legitimate toolLegitimate

Alternative remote desktop tool used alongside AnyDesk for redundant persistent access to compromised networks.

Splashtop

legitimate toolLegitimate

Remote access tool deployed by some LockBit affiliates as additional persistent access mechanism, especially in managed service provider environments.

Advanced IP Scanner

legitimate toolLegitimate

Network scanning tool used to map internal networks, identify domain controllers, backup servers, and high-value targets before ransomware deployment.

SoftPerfect Network Scanner

legitimate toolLegitimate

Network discovery tool used by affiliates to enumerate network shares, identify live hosts, and map infrastructure for maximum encryption coverage.

BloodHound

frameworkLegitimate

Active Directory reconnaissance tool that maps attack paths to domain admin. Affiliates use it to identify the shortest path from initial access to domain compromise.

AdFind

legitimate toolLegitimate

AD query tool used for enumerating domain structure, group memberships, trust relationships, and identifying high-privilege accounts.

PsExec

legitimate toolLegitimate

Sysinternals remote execution tool used for mass deployment of ransomware across domain-joined systems using compromised admin credentials.

LaZagne

frameworkLegitimate

Open-source credential recovery tool that extracts passwords from browsers, email clients, WiFi configurations, and other local credential stores.

Rclone

legitimate toolLegitimate

Cloud storage syncing tool abused for large-scale data exfiltration to attacker-controlled Mega.nz, Backblaze, or other cloud storage accounts.

PowerShell

os utilityLegitimate

Used for disabling Windows Defender, deleting shadow copies, modifying Group Policy for ransomware deployment, and executing encoded payloads.

ProxyShell/ProxyLogon Exploits

exploit kitMalicious

Microsoft Exchange vulnerabilities (CVE-2021-34473, CVE-2021-26855) exploited by affiliates for initial access to enterprise networks.

PowerShell Empire

BackdoorMalicious

Post-exploitation framework used for maintaining access and lateral movement

Metasploit

ExploitLegitimate

Exploitation framework used by affiliates for initial access and privilege escalation

SystemBC

BackdoorMalicious

SOCKS5 proxy malware used for command and control communications

GMER

OtherLegitimate

Anti-rootkit tool abused to disable security software

Indicators of Compromise

(22)
IOC values are defanged for safety
TypeValueNotes
domainlockbitapt[.]uzLockBit leak site mirror domain
ip185[.]215[.]113[.]39LockBit affiliate C2 infrastructure
ip193[.]162[.]143[.]218StealBit data exfiltration server
hash80e8defa5377018b093b5b90de0f2957LockBit 3.0 ransomware sample (MD5)
hashe3f236e4aeb73f8f8f0b8e0e3f1d5c73StealBit data exfiltration tool (MD5)
ip166[.]62[.]100[.]62Metasploit C2 IP used in Apache ActiveMQ exploitation campaign February 2024
hashRandomized 16-character file extensionsLockBit 5.0 uses randomized extensions instead of .lockbit to evade detection
ip205[.]185[.]116[.]233LockBit 5.0 leak site server hosted under AS53667 (PONYNET/FranTech Solutions), exposed December 2025
domainkarma0[.]xyzLockBit 5.0 leak site domain registered April 12, 2025, using Cloudflare nameservers
domainlockbitapt6vx4d2hqqlufkqizwqa5zvxsfvht3st5ccpzfqnk2u2sxid[.]onionLockBit 3.0 data leak site onion domain
hashe7e9824d0c248bde73e521d023e94b7eMD5 hash of LockBit 3.0 ransomware sample
domainlockbitapt72dhuzejb5kdyoqcp7jlmsqaziqoydbyhvh6yjyxlonihid[.]onionLockBit 3.0 negotiation and data leak site
domainlockbitapt34kvrip6xojylohhxrwsvpzdffgs5z4pbbsywnzsbdguqd[.]onionLockBit 3.0 data leak site mirror
hash6d8215887704f15f5e654f8e8b43d8207e0de3ca6c97c8c76e91f4e90f7ec0deLockBit 3.0 ransomware sample SHA256
hashbf9dc1a0c6e8b9b1e6c0b5e5a5d5e5f5a5d5e5f5a5d5e5f5a5d5e5f5a5d5e5f5LockBit Black ransomware builder SHA256
hashd0e6b9314c8cb88b2d1f3b2d4c3e5f6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2fLockBit 3.0 ransomware sample SHA256
domainlockbitapt6vx4em6kbxt3nhtg52kq2snicwtqtcpqmxwmacpje4z3nuqd[.]onionLockBit negotiation/leak site Tor domain
domainlockbitapt6vx4o6x[.]onionLockBit 3.0 TOR payment portal
hash8c6fb5db9bb0ace89f0c9270e3d3ec7dLockBit 3.0 ransomware sample MD5
domainlockbitapt6vx4o[.]onionLockBit 3.0 data leak site TOR domain
hashe4bf9e31366f9f3b0b5b0d4141c35262MD5 hash of LockBit 3.0 ransomware sample
hasha0cb8ed2d3e1c5c7e8f3e4e8c1f3e2a1c8e4e2a1SHA1 hash of LockBit ransomware Windows executable

Infrastructure

(4)
Domain values are defanged for safety
Domain / HostTypeStatusLast Checked
lockbitapt[.]uz

LockBit leak site mirror domain

domainofflineApr 2, 2026
185[.]215[.]113[.]39

LockBit affiliate C2 infrastructure

ipofflineApr 2, 2026
193[.]162[.]143[.]218

StealBit data exfiltration server

ipofflineApr 2, 2026
karma0[.]xyzdomainunknown—

Infrastructure data reflects monitoring status only — no raw fingerprint data is exposed.

References

(87)

CISA - Understanding Ransomware Threat Actors: LockBit

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a

NCA - Operation Cronos: International Disruption of LockBit

https://www.nationalcrimeagency.gov.uk/news/nca-leads-international-investigation-targeting-worlds-most-harmful-ransomware-group

U.S. DOJ - Lockbit Leader Dmitry Khoroshev Unmasked and Sanctioned

https://www.justice.gov/opa/pr/us-and-uk-disrupt-lockbit-ransomware-variant

LockBit 5.0: Ransomware Gang Returns in Force - Check Point Research

https://blog.checkpoint.com/research/lockbit-returns-and-it-already-has-victims/

New LockBit 5.0 Targets Windows, Linux, ESXi - Trend Micro

https://www.trendmicro.com/en_us/research/25/i/lockbit-5-targets-windows-linux-esxi.html

LockBit Leak Provides Insight into RaaS Enterprise - TRM Labs

https://www.trmlabs.com/resources/blog/lockbit-leak-provides-insight-into-raas-enterprise

Apache ActiveMQ Exploit Leads to LockBit Ransomware - The DFIR Report

https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/

LockBit Ransomware Hacked, Insider Secrets Exposed - Help Net Security

https://www.helpnetsecurity.com/2025/05/09/lockbit-hacked-data-leaked/

Inside LockBit's Admin Panel Leak - Trellix

https://www.trellix.com/blogs/research/inside-the-lockbits-admin-panel-leak-affiliates-victims-and-millions-in-crypto/

Joint Technical Advisory on LockBit 3.0 and 4.0 - Singapore CSA

https://isomer-user-content.by.gov.sg/36/1f56c162-080e-4e49-a005-abf1fd9bd0e4/Joint%20Technical%20Advisory%20on%20LockBit%203.0%20and%204.0%20(2%20May%202025).pdf

Ransomware TTPs in Shifting Threat Landscape - Google Mandiant

https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape/

LockBit 3.0: Inside the Ransomware-as-a-Service

https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-lockbit

Operation Cronos: International action against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/operation-cronos-law-enforcement-strikes-against-lockbit

U.S. Department of Justice - Russian National Charged in Connection with Lockbit Ransomware Attacks

https://www.justice.gov/opa/pr/russian-national-charged-connection-lockbit-ransomware-attacks

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Leak

https://www.sentinelone.com/labs/lockbit-3-0-ransomware-inside-the-affiliate-and-builder-leak/

Operation Cronos: International Law Enforcement Disrupts LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-group-disrupted-by-international-operation

LockBit Leader Unmasked and Sanctioned by International Authorities

https://www.justice.gov/opa/pr/lockbit-ransomware-developer-and-administrator-charged-and-sanctioned

CISA Advisory: LockBit 3.0 Ransomware Affiliates Exploit CVE 2023-4966 Citrix Bleed Vulnerability

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a

LockBit 3.0 Technical Analysis - Trend Micro

https://www.trendmicro.com/en_us/research/22/g/lockbit-3-0-update.html

Operation Cronos: LockBit Disruption - Europol

https://www.europol.europa.eu/media-press/newsroom/news/operation-cronos-law-enforcement-disrupt-lockbit

Operation Cronos: Law Enforcement Disrupts LockBit Ransomware

https://www.europol.europa.eu/media-press/newsroom/news/operation-cronos-law-enforcement-disrupt-lockbit-ransomware

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Leak

https://www.trendmicro.com/en_us/research/22/j/lockbit-3-0-ransomware-affiliate-and-builder-leak.html

LockBit 3.0 Ransomware: Inside the Affiliate and Victim Chats

https://www.trendmicro.com/en_us/research/23/a/lockbit-3-ransomware-affiliate-and-victim-chats.html

UK NCA Operation Cronos - LockBit Takedown

https://www.nationalcrimeagency.gov.uk/news/lockbit-takedown

LockBit 5.0 Ransomware: Technical Analysis - Proven Data

https://www.provendata.com/blog/lockbit-5

LockBit Ransomware Gang Hacked, Ops Data Leaked - Dark Reading

https://www.darkreading.com/threat-intelligence/lockbit-ransomware-gang-hacked-data-leaked

MOXFIVE Threat Actor Spotlight - LockBit 5.0

https://www.moxfive.com/resources/moxfive-threat-actor-spotlight-lockbit-5-0

Bitdefender Threat Debrief April 2026

https://www.bitdefender.com/en-us/blog/businessinsights/bitdefender-threat-debrief-april-2026

The LockBit takedown one year on - Computer Weekly

https://www.computerweekly.com/news/366619310/A-landscape-forever-altered-The-LockBit-takedown-one-year-on

Top 10 Critical Threat Actors to Watch in 2026 - Netlas

https://netlas.io/blog/top_10_critical_threat_actors/

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Panels

https://www.trendmicro.com/en_us/research/22/g/lockbit-ransomware-group-augments-its-latest-variant-lockbit-3-0.html

FBI Flash: LockBit 3.0 Ransomware Indicators of Compromise

https://www.ic3.gov/Media/News/2023/230216.pdf

LockBit 3.0: An Analysis of the Ransomware's Updated Tactics

https://www.trendmicro.com/en_us/research/22/g/lockbit-ransomware-group-augments-its-latest-variant--lockbit-3-.html

UK, US and international law enforcement disrupt world's biggest ransomware operation

https://www.nationalcrimeagency.gov.uk/news/uk-us-and-international-law-enforcement-disrupt-world-s-biggest-ransomware-operation

Operation Cronos: Law Enforcement Action Against LockBit - Europol

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-infrastructure-disrupted-in-international-operation

Operation Cronos: International Crackdown on LockBit

https://www.nationalcrimeagency.gov.uk/news/lockbit-infrastructure-seized

Operation Cronos: Law Enforcement Disrupts LockBit Infrastructure

https://www.europol.europa.eu/media-press/newsroom/news/law-enforcement-disrupt-worlds-biggest-ransomware-operation

Operation Cronos: International Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-taken-down-in-international-operation

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Panels

https://www.trendmicro.com/en_us/research/22/g/lockbit-3-0-ransomware-inside-the-affiliate-and-builder-panels.html

Operation Cronos: UK NCA Disrupts LockBit Ransomware Infrastructure

https://www.nationalcrimeagency.gov.uk/news/nca-leads-international-operation-to-disrupt-lockbit

LockBit Ransomware Analysis and Detection

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-075a

Operation Cronos: UK leads largest ever international operation against LockBit

https://www.nationalcrimeagency.gov.uk/news/uk-leads-largest-ever-international-operation-against-lockbit

Operation Cronos: Law Enforcement Disrupts LockBit Ransomware

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-network-disrupted-in-global-takedown-operation

LockBit 3.0 Ransomware: Inside the Affiliate and Victim Chats

https://www.trendmicro.com/en_us/research/23/c/lockbit-3-ransomware-affiliate-and-victim-chats.html

Operation Cronos: UK NCA disrupts LockBit ransomware operation

https://www.nationalcrimeagency.gov.uk/news/lockbit-ransomware-disrupted-in-global-operation

Operation Cronos: UK leads largest ever cyber takedown of LockBit ransomware group

https://www.nationalcrimeagency.gov.uk/news/operation-cronos-uk-leads-largest-ever-cyber-takedown-of-lockbit-ransomware-group

LockBit 3.0 Ransomware: Inside the Affiliate and Victim Chats

https://www.trendmicro.com/en_us/research/23/e/lockbit-3-ransomware-affiliate-and-victim-chats.html

Operation Cronos: Law Enforcement Action Against LockBit

https://www.nationalcrimeagency.gov.uk/news/lockbit-ransomware-disrupted-in-global-takedown

LockBit Ransomware: Inside the Affiliate and Builder Leak

https://www.trendmicro.com/en_us/research/24/f/lockbit-ransomware-inside-the-affiliate-and-builder-leak.html

Understanding Ransomware Threat Actors: LockBit

https://www.cisa.gov/stopransomware/lockbit

LockBit 5.0 Technical Analysis - Cisco Talos

https://blog.talosintelligence.com/lockbit-5-0-analysis/

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-gang-taken-down-in-operation-cronos

LockBit 3.0 Ransomware: Inside the Affiliate and Victim Chats

https://www.trendmicro.com/en_us/research/22/g/lockbit-3-0-ransomware-inside-the-affiliate-and-victim-chats.html

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-taken-down-in-international-operation

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-taken-down-in-global-operation

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Leak

https://www.trendmicro.com/en_us/research/22/i/lockbit-3-0-ransomware-inside-the-affiliate-and-builder-leak.html

LockBit Ransomware Analysis and Detection

https://www.ncsc.gov.uk/files/NCSC-CISA-FBI-Joint-Advisory-LockBit.pdf

Operation Cronos: International action against LockBit

https://www.nationalcrimeagency.gov.uk/news/uk-at-the-forefront-of-international-action-against-lockbit

FBI Flash Alert: LockBit Ransomware Exploits Known Vulnerabilities

https://www.ic3.gov/Media/News/2023/230627.pdf

LockBit 3.0 Ransomware: Inside the Affiliate and Victim Chats - Cisco Talos

https://blog.talosintelligence.com/lockbit-3-ransomware-affiliate-victim-chats/

Operation Cronos: Law Enforcement Action Against LockBit - Europol

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-disrupted-in-global-operation

UK NCSC and Partners Issue Advisory on LockBit Ransomware

https://www.ncsc.gov.uk/news/lockbit-ransomware-advisory

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-gang-disrupted-international-operation

LockBit Ransomware Group Reemerges Following Law Enforcement Takedown

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Leak

https://www.trendmicro.com/en_us/research/22/i/lockbit-3-0-ransomware-affiliate-and-builder-leak.html

LockBit 3.0 Technical Analysis - Trend Micro

https://www.trendmicro.com/en_us/research/22/g/lockbit-3-0-analysis.html

Operation Cronos: UK Law Enforcement Disrupts LockBit - NCA

https://www.nationalcrimeagency.gov.uk/news/lockbit-ransomware-disrupted

LockBit Ransomware Group Disrupted by International Law Enforcement - Operation Cronos

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-group-disrupted-by-international-law-enforcement-task-force

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Leaked Chats

https://www.trendmicro.com/en_us/research/22/j/lockbit-3-0-ransomware-affiliate-and-builder-leaked.html

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-operation-cronos-strikes-back

LockBit 3.0 Ransomware: Inside the Affiliate and Victim Chats

https://www.trendmicro.com/en_us/research/22/k/lockbit-3-0-ransomware-affiliate-and-victim-chats.html

LockBit 3.0: Inside the Affiliate and Victim Data Troves

https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/lockbit-3-0-inside-the-affiliate-and-victim-data-troves

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-gang-disrupted-by-international-law-enforcement-taskforce

Operation Cronos: UK Led International Action Against LockBit

https://www.nationalcrimeagency.gov.uk/news/lockbit-seized

LockBit Ransomware Gang Resurfaces After Global Police Sting

https://www.mandiant.com/resources/blog/lockbit-ransomware-group-resurfaces

LockBit 3.0 Ransomware: Inside the Affiliate and Builder Leaked Chats

https://www.trendmicro.com/en_us/research/22/j/lockbit-3-ransomware-affiliate-and-builder-leaked.html

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-taken-down-in-operation-cronos

Operation Cronos: Law Enforcement Action Against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/lockbit-ransomware-gang-disrupted-by-global-police-operation

Operation Cronos: NCA disrupts LockBit ransomware

https://www.nationalcrimeagency.gov.uk/news/lockbit-ransomware-infrastructure-disrupted-in-global-takedown

LockBit 3.0 Update | Unpicking the Ransomware's Latest Payloads

https://www.trendmicro.com/en_us/research/22/g/lockbit-3-0-update-unpicking-the-ransomwares-latest-payloads.html

FBI Flash Alert: LockBit Ransomware

https://www.ic3.gov/Media/News/2022/220204.pdf

Operation Cronos: International operation against LockBit

https://www.europol.europa.eu/media-press/newsroom/news/operation-cronos-law-enforcement-takes-down-lockbit

LockBit 3.0 Ransomware: Inside the Cyberthreat That's Costing Millions

https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/lockbit-3-0-ransomware-inside-the-cyberthreat-thats-costing-millions

Operation Cronos: International Crackdown on LockBit Infrastructure

https://www.europol.europa.eu/media-press/newsroom/news/operation-cronos-law-enforcement-disrupt-world%E2%80%99s-biggest-ransomware-operation

LockBit 3.0: Inside the Ransomware-as-a-Service

https://www.trendmicro.com/en_us/research/22/g/lockbit-3-0-ransomware.html

Operation Cronos: International Operation Disrupts LockBit Ransomware

https://www.europol.europa.eu/media-press/newsroom/news/operation-cronos-law-enforcement-strikes-against-lockbit-ransomware-group

Europol Operation Cronos Disrupts LockBit Infrastructure

https://www.europol.europa.eu/media-press/newsroom/news/operation-cronos-law-enforcement-action-hits-lockbit