Threat Intelligence / Actor / LockBit

LockBit

As of 2026-09-08, LockBit is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning ransomware hacktivism, ransomware, threat intel. Also known as ABCD ransomware, Hydra, LockBitSupp, LockBit Gang. ATT&CK coverage spans 128 techniques across 16 tactics in 8 of 8 tracked threats. Most-observed techniques: T1486 (Data Encrypted for Impact), T1078 (Valid Accounts), T1685 (Disable or Modify Tools).

Nation: Russia · 8 tracked threat(s) · Categories: RANSOMWARE_HACKTIVISM, RANSOMWARE, THREAT_INTEL, MALWARE

Also known as: ABCD ransomware, Hydra, LockBitSupp, LockBit Gang

ATT&CK techniques observed

128 techniques observed across 8 of 8 tracked threats · Discovery (18), Defense Evasion (17), Execution (15), Persistence (12), Resource Development (12), Command And Control (11)

Tracked threats

Related CVEs

13 CVEs referenced by tracked LockBit activity

CVE-2025-61884, CVE-2025-61882, CVE-2025-33073, CVE-2025-32433, CVE-2024-55591, CVE-2024-47575, CVE-2023-4967, CVE-2023-4966, CVE-2023-27350, CVE-2023-0669, CVE-2020-0796, CVE-2018-13379, CVE-2015-2291

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence