Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

LockBit

Ransomware 7 detections found

Also known as: LockBit 3.0, LockBit Black, LockBit Red, Bitwise Spider, ABCD

LockBit is a Ransomware-as-a-Service (RaaS) operation active since 2019 that became the most prolific ransomware brand of 2022-2023, using double extortion (data theft plus encryption) against organizations of all sizes worldwide. In February 2024, the FBI, UK NCA, and international partners executed 'Operation Cronos,' seizing LockBit's infrastructure, obtaining decryption keys, and indicting/sanctioning several members including administrator Dmitry Khoroshev. Despite the takedown, splinter activity and rebrand attempts (e.g., LockBit 4.0) have continued at reduced scale into 2025-2026.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
splunk Fsutil Zeroing File production 2026-05-13
splunk UAC Bypass With Colorui COM Object production 2026-05-13
splunk Windows Modify Registry Default Icon Setting production 2026-05-13
sigma ESXi Storage Information Discovery Via ESXCLI test 2023-09-04
sigma Disabled Windows Defender Eventlog test 2023-08-17
suricata ET INFO HTTP Request to Lockbit Ransomware Payment Domain rev 3 2023-05-22
snort ET INFO HTTP Request to Lockbit Ransomware Payment Domain rev 4 2023-05-22