LockBit
MITRE G1040Also known as Lockbit5, LockBit5, Lockbit, LockBit 3.0, LockBit, Lockbit 5.0, LockBit 5, LockBit Black
Reports
91
First seen
Jan 17, 2024
Last seen
Aug 5, 2026
Motivation
Financial
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×2×8
United States×8
Brazil×6
Netherlands×5
Thailand×4
Germany×4
Dominican Republic×2
United Kingdom×2
Taiwan×2
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1486 Data Encrypted for Impact ×8T1566 Phishing ×5T1027 Obfuscated Files or Information ×3T1190 Exploit Public-Facing Application ×3T1562.001 Impair Defenses: Disable or Modify Tools ×2T1489 Service Stop ×2T1070.001 Indicator Removal: Clear Windows Event Logs ×2T1005 Data from Local System ×2T1567 Exfiltration Over Web Service ×2T1105 Ingress Tool Transfer ×2T1059.003 Windows Command Shell ×2T1195 Supply Chain Compromise ×2
Indicators
domain ×93filename ×71hash_sha256 ×19ip_v4 ×11cve ×5hash_md5 ×2url ×1hash_sha1 ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High