🇷🇺 LockBit¶
Threat-actor battle card · maintained from public sources · last updated 2026-08-25 · also known as LockBit 5.0, ABCD (origin)
Overview¶
LockBit emerged in 2019 (initially "ABCD") and industrialised RaaS at scale before Operation Cronos seized its infrastructure in February 2024. It rebuilt within weeks; LockBit 5.0 was announced on the RAMP forum in September 2025 (the group's six-year anniversary) and a Christmas-themed 5.0 DLS launched December 2025, quickly posting 100+ alleged victims. Active member of the Qilin/LockBit/DragonForce ransomware cartel (formed September 2025), which together with The Gentlemen and Akira accounted for 49.5% of all global ransomware attacks in Q2 2026 per ZeroFox. 163 victims in Q1 2026 (+106% vs Q4 2025, rank #4 globally); estimated 179 victims in May 2026 alone (36% of all May DLS posts per Cybersecurity Dive); 311 confirmed victims YTD as of June 20, 2026 (+87% month-on-month May→June); 335 YTD as of Aug 17, 2026 (~24 new victims in the 8 weeks following (14 in the most recent 30 days per ransomware.live). Notable geographic shift: US share fell from historically 50%+ to 21.2% of Q1 2026 victims, with Italy, Brazil, and Turkey absorbing the balance — deliberate targeting diversification to reduce law-enforcement exposure. July–August 2026 activity: at least 5 new postings in July's first two weeks (ComTRI GmbH/Germany/IT, Gies Dienstleistungen/Germany/facilities, A. Bianchini/Spain/manufacturing, Hotel de la Bourse/France/hospitality, JS Hotels/Spain/hospitality — all 🟥 unverified); last observed activity Aug 20, 2026. Top targeted sectors: Manufacturing (18%), Professional Services (17%), Technology (13%), spanning 68 countries as of Aug 2026.
Tradecraft¶
- Cross-platform 5.0 ("ChuongDong"): Windows, Linux and ESXi variants (4 build types released Jan 14, 2026:
LB_Black,LB_Linux,LB_ESXi,LB_ChuongDong); randomized 16-character extensions; Russian-language system avoidance. - Windows binary: heavy obfuscation/packing, DLL reflection, ETW patching (
EtwEventWritepatched in-memory to blind EDR telemetry), security-service termination; payloads reflection-loaded from memory (no disk artifact). - Social engineering: impersonating IT/help-desk via Microsoft Teams to push remote-access tools (Quick Assist).
- ~80% Windows targets, ~20% ESXi/Linux; double-extortion model with dedicated Tor leak portal.
- Refreshed affiliate incentive model to re-recruit operators post-Operation Cronos disruption.
Notable recent victims¶
- Central Romana Corporation (Dominican Republic, agribusiness)
- Shougang Hierro Perú (mining)
- DaikyoNishikawa (Japan, automotive parts); Sierra Vista Hospital (US healthcare)
- Clarinda Regional Health Center (Iowa, USA — healthcare; attack Oct 2025, 24,341 patient records including SSNs; breach notification letters mailed June 2026)
- ComTRI GmbH (Germany, IT services, July 2026 🟥); Gies Dienstleistungen GmbH (Germany, facilities, July 2026 🟥); JS Hotels (Spain, 10-property hospitality group, July 2026 🟥)
Assessment¶
A resilient brand that survived a global law-enforcement takedown and rebuilt at scale via its affiliate network. The ESXi focus, ETW blinding, and Teams-based help-desk social engineering are the headline risks. The Qilin/DragonForce/LockBit cartel is operationally confirmed as of Q2 2026 and accounts for ~30% of all global ransomware DLS postings on its own; the DOJ's July 16, 2026 bulletproof-hosting indictment targeting Media Land (used by LockBit, Cl0p, and Play) is the first direct counter-cartel infrastructure action naming LockBit-adjacent operations since Operation Cronos. The deliberate US targeting reduction in Q1 2026 remains operationally notable — spreading geographic risk in response to the February 2024 Operation Cronos and subsequent US/UK/Australian sanctions on named affiliates. As of August 2026, LockBit is posting at a slower pace (~14 new victims in the last 30 days vs. an estimated 179 in May 2026 alone), consistent with affiliate-base attrition following the BPH indictment. Available evidence does not establish that the original pre-Cronos central organization has recovered its former operational tempo; the brand persists primarily as an affiliate franchise. Watch for any renewed affiliate-recruitment push or infrastructure rebuild event.
Sources¶
- Trend Micro — New LockBit 5.0 Targets Windows, Linux, ESXi
- Check Point — LockBit 5.0: Ransomware Gang Returns in Force
- Picus — The LockBit Comeback After a Global Takedown
- Check Point Research — State of Ransomware Q1 2026
- Industrial Cyber — Ransomware sector reconsolidating Q1 2026
- Check Point Research — June 2026 Ransomware Report (LockBit rank, 7% global share)
- ZeroFox — Q2 2026 Ransomware Wrap-Up (five-group cartel, 49.5%)
- GBHackers — LockBit 5.0 Affiliate Panel and Build Variants Exposed (Jan 2026)
- TechTimes — DOJ Charges Russians Who Ran Hosting Infrastructure for LockBit, Cl0p, Play (Jul 16, 2026)
- HIPAA Journal — Clarinda Regional Health Center (LockBit5 Oct 2025 attack, 24,341 patients)
- DeXpose — LockBit Ransomware Threat Intelligence Guide (2026)
- CybelAngel — LockBit Ransomware: Attack Methods and 2026 Status
- Ransomware.live — LockBit 5.0 group stats (as of Aug 17, 2026)
- Arete — LockBit 5.0: The RaaS That Refuses to Go Away
🗂️ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
July 2026
June 2026