Threat Intelligence / Actor / LockBit
LockBit
As of 2026-09-08, LockBit is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 8 threats spanning ransomware hacktivism, ransomware, threat intel. Also known as ABCD ransomware, Hydra, LockBitSupp, LockBit Gang. ATT&CK coverage spans 128 techniques across 16 tactics in 8 of 8 tracked threats. Most-observed techniques: T1486 (Data Encrypted for Impact), T1078 (Valid Accounts), T1685 (Disable or Modify Tools).
Also known as: ABCD ransomware, Hydra, LockBitSupp, LockBit Gang
ATT&CK techniques observed
- T1486 Data Encrypted for Impact — Impact — observed in 8 of 8 tracked threats
- T1078 Valid Accounts — Initial Access — observed in 7 of 8 tracked threats
- T1685 Disable or Modify Tools — Defense Impairment — observed in 7 of 8 tracked threats
- T1021 Remote Services — Lateral Movement — observed in 6 of 8 tracked threats
- T1070 Indicator Removal — Defense Evasion — observed in 6 of 8 tracked threats
- T1133 External Remote Services — Initial Access — observed in 6 of 8 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 6 of 8 tracked threats
- T1005 Data from Local System — Collection — observed in 5 of 8 tracked threats
- T1027 Obfuscated Files or Information — Defense Evasion — observed in 5 of 8 tracked threats
- T1036 Masquerading — Defense Evasion — observed in 5 of 8 tracked threats
- T1059 Command and Scripting Interpreter — Execution — observed in 5 of 8 tracked threats
- T1190 Exploit Public-Facing Application — Initial Access — observed in 5 of 8 tracked threats
- T1490 Inhibit System Recovery — Impact — observed in 5 of 8 tracked threats
- T1003 OS Credential Dumping — Credential Access — observed in 4 of 8 tracked threats
- T1055 Process Injection — Defense Evasion — observed in 4 of 8 tracked threats
Tracked threats
- France Threat Landscape: Qilin/MedusaLocker/LockBit Ransomware and NoName057(16) Hacktivist DDoS Campaign Amid 4x Dark Web Activity Surge — HIGH
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion Demands — MEDIUM
- Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026) — INFO
- Q1 2026 Ransomware Landscape: Qilin Dominance, LockBit 5.0 Comeback, and FortiGate (CVE-2024-55591) / Oracle EBS (CVE-2025-61882) Mass Exploitation — CRITICAL
- Human-Operated Ransomware via GPO Abuse — Domain-Wide Encryption Through Group Policy Weaponization — HIGH
- Ransomware C2 Infrastructure Abuse — Bulletproof Hosting Procurement, VPS Exploitation, Hosting Panel Compromise, Cobalt Strike on Legitimate Infrastructure, Multi-Jurisdictional Takedown Complexity — HIGH
- LockBit 5.0 Cross-Platform Ransomware Analysis — CRITICAL
- BYOVD EDR Killer Tooling — Ransomware Groups Weaponizing Signed Kernel Drivers to Blind Endpoint Detection — HIGH
Related CVEs
CVE-2025-61884, CVE-2025-61882, CVE-2025-33073, CVE-2025-32433, CVE-2024-55591, CVE-2024-47575, CVE-2023-4967, CVE-2023-4966, CVE-2023-27350, CVE-2023-0669, CVE-2020-0796, CVE-2018-13379, CVE-2015-2291
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →