🏹 LockBit — Ransomware
LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions.
Classification
Ransomware
Leak-site victims
5
Ransomware.live
Associated IoCs
0
local intel
MITRE techniques
3
ATT&CK
Tracked
Yes
Ransomware.live
🛡 MITRE ATT&CK Techniques
T1486 Data Encrypted for ImpactT1490 Inhibit System RecoveryT1567 Exfiltration Over Web Service🔥 Leak-Site Victims (5)
| Victim | Country | Published | Domain |
|---|---|---|---|
| Bangkok Airways | TH | 2021-08-23T00:00:00+00:00 | — |
| Accenture | 2021-07-30T00:00:00+00:00 | — | |
| Merseyrail (Rail network) | GB | 2021-04-01T00:00:00+00:00 | — |
| Kopter | CH | 2020-11-30T00:00:00+00:00 | — |
| Press Trust of India (PTI) | IN | 2020-10-21T00:00:00+00:00 | — |
Source: Ransomware.live leak-site monitoring (cached, offline-safe).
📁 Case Management
🏹 Campaigns & malware
🏹 Add to case
🧩 Advanced Capabilities
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron