Ransomware
LockBit
Ransomware
7 detections found
Also known as: LockBit 3.0, LockBit Black, LockBit Red, Bitwise Spider, ABCD
LockBit is a Ransomware-as-a-Service (RaaS) operation active since 2019 that became the most prolific ransomware brand of 2022-2023, using double extortion (data theft plus encryption) against organizations of all sizes worldwide. In February 2024, the FBI, UK NCA, and international partners executed 'Operation Cronos,' seizing LockBit's infrastructure, obtaining decryption keys, and indicting/sanctioning several members including administrator Dmitry Khoroshev. Despite the takedown, splinter activity and rebrand attempts (e.g., LockBit 4.0) have continued at reduced scale into 2025-2026.
Detection & eradication references
Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.
- #StopRansomware: LockBit 3.0 — CISA/FBI/MS-ISAC
- LockBit 3.0, Software S1202 — MITRE ATT&CK
- US and UK Disrupt LockBit Ransomware Variant — U.S. Department of Justice
Detection rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| splunk | Fsutil Zeroing File | production | 2026-05-13 |
| splunk | UAC Bypass With Colorui COM Object | production | 2026-05-13 |
| splunk | Windows Modify Registry Default Icon Setting | production | 2026-05-13 |
| sigma | ESXi Storage Information Discovery Via ESXCLI | test | 2023-09-04 |
| sigma | Disabled Windows Defender Eventlog | test | 2023-08-17 |
| suricata | ET INFO HTTP Request to Lockbit Ransomware Payment Domain | rev 3 | 2023-05-22 |
| snort | ET INFO HTTP Request to Lockbit Ransomware Payment Domain | rev 4 | 2023-05-22 |