Actor Profile

🏹 LockBit — Ransomware

LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions.

Classification

Ransomware

Leak-site victims

5
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

3
ATT&CK

Tracked

Yes
Ransomware.live

🛡 MITRE ATT&CK Techniques

T1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1567 Exfiltration Over Web Service

🔥 Leak-Site Victims (5)

VictimCountryPublishedDomain
Bangkok Airways TH 2021-08-23T00:00:00+00:00
Accenture 2021-07-30T00:00:00+00:00
Merseyrail (Rail network) GB 2021-04-01T00:00:00+00:00
Kopter CH 2020-11-30T00:00:00+00:00
Press Trust of India (PTI) IN 2020-10-21T00:00:00+00:00

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach LockBit (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php