Threat Actor Profile

Lockbit

Lockbit ransomware, first identified in 2019, is a highly sophisticated global cyber threat. Known for its ransomware-as-a-service (RaaS) model, it enables affiliates to execute devastating attacks across industries. Leveraging double extortion tactics, Lockbit encrypts sensitive data and demands ransoms, often targeting large organizations worldwide. Its agility and operational efficiency have made it one of the most notorious ransomware groups.


Threat Actor Profile

Lockbit

Fancy Bear TTPs

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Country of Origin

Lockbit's country of origin remains unknown. However, cybersecurity experts suggest that it likely operates from regions with limited law enforcement oversight, possibly Eastern Europe or Russia, due to linguistic patterns and its focus on avoiding targets in CIS (Commonwealth of Independent States) countries.

Members

The exact size of Lockbit's membership is unknown, but it is believed to consist of a core development team managing the ransomware and an extensive network of affiliates who carry out the attacks. Affiliates are usually recruited through underground forums and receive a share of the ransom payments they collect.

Leadership

The leadership structure of Lockbit is shrouded in mystery. No publicly known names or aliases have been definitively tied to the group. Experts speculate that it likely follows a decentralized leadership model, characteristic of many RaaS operations.

Tactics

Lockbit’s primary objective is financial gain through ransomware deployment. It focuses on high-profile organizations to ensure substantial ransom payments while utilizing extortion to amplify pressure on victims.


Techniques

The group uses advanced penetration tools like Cobalt Strike to compromise networks. Initial access is often gained through phishing campaigns or exploiting vulnerabilities in remote desktop services. Lockbit is also known to bypass endpoint security measures using sophisticated methods.


Procedures

Lockbit utilizes double extortion techniques, encrypting victim data and threatening to release it publicly if demands are not met. They often deploy custom malware variants and adapt quickly to overcome new cybersecurity defenses.


Want to shut down threats before they start?

Indicators of Compromise (IOCs)

Organizations should monitor for:

  • Known Fancy Bear malware signatures (e.g., XAgent, ADVSTORESHELL).
  • Suspicious domains mimicking government or defense entities.
  • Zero-day exploits in applications like Microsoft Windows and Adobe Flash.
  • Abnormal network traffic patterns indicating command-and-control communications.

Key Victims

Fancy Bear targets include:

  • Governments (United States, Germany, France, Ukraine, and others).
  • Military Organizations (focus on NATO-aligned entities).
  • Media Outlets and Journalists (especially those covering Kremlin-related topics).
  • Critical Infrastructure (energy, aerospace, and defense).
  • International Sporting Organizations (e.g., WADA).
  • Political Groups (e.g., the Democratic National Committee).

Notable Cyber Attacks

Aenean interdum tempor lectus, nec rutrum nisl interdum ut. Aliquam mattis felis vulputate dui ultrices, ac finibus ligula interdum. Proin metus enim, sagittis fringilla viverra quis, pulvinar sit amet quam. Donec eget ullamcorper nibh. Praesent a nisl eu nunc interdum efficitur.

Notable Cyberattacks

One of Lockbit's most significant operations occurred in mid-2021, where they orchestrated multiple attacks on international corporations. These incidents resulted in stolen intellectual property being posted on data leak websites, damaging reputations and disrupting operations.


Glitch effectGlitch effect

How to Defend Against Lockbit

1

Implement secure backups, conduct frequent vulnerability assessments, and deploy endpoint detection and response (EDR) solutions. 

2

Huntress Managed EDR enhance protection by monitoring for early signs of compromise and swiftly responding to ransomware activity.


Huntress solutions help protect organizations by monitoring endpoints, detecting intrusions, and mitigating Lockbit threats with enterprise-grade technology.

Law Enforcement & Arrests

Law enforcement has made strides in targeting Lockbit affiliates. For example, in November 2022, a Russian national suspected of developing and operating the ransomware was charged by U.S. authorities. However, the decentralized affiliate model complicates complete disruption of their operations.

References

Related Threat Actor Profiles

Notable developments include the U.S. indictment of GRU-affiliated officers in 2018. Despite these measures, Fancy Bear remains operational, emphasizing the challenges of deterring state-sponsored cyber actors.

Detect, Respond, Protect

See how the global Huntress SOC can augment your team
with 24/7 coverage and unmatched human expertise.
Start your free trial today.

Try Huntress for Free