Threat Intelligence / Actor / LockBit — referenced only as the illustrative test sample in the cited detection research

LockBit — referenced only as the illustrative test sample in the cited detection research

As of 2026-07-22, LockBit — referenced only as the illustrative test sample in the cited detection research is a Russia (affiliate nationals per 2024 DOJ/Operation Cronos indictments; LockBit is a financially motivated criminal RaaS operation, not confirmed state-sponsored)-nexus threat actor tracked by Threadlinqs Intelligence across 1 threat spanning threat intel. Also known as LockBit (LockBit Ransomware-as-a-Service operation) — referenced only as the illustrative test sample in the cited detection research.

Nation: Russia (affiliate nationals per 2024 DOJ/Operation Cronos indictments; LockBit is a financially motivated criminal RaaS operation, not confirmed state-sponsored) · 1 tracked threat(s) · Categories: THREAT_INTEL

Also known as: LockBit — referenced only as the illustrative test sample in the cited detection research, LockBit (LockBit Ransomware-as-a-Service operation) — referenced only as the illustrative test sample in the cited detection research

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence