Skip to content

🇷🇺 LockBit

Threat-actor battle card · maintained from public sources · last updated 2026-08-25 · also known as LockBit 5.0, ABCD (origin)

CategoryRansomware-as-a-Service
AttributionRussia-affiliated (Russian-language system avoidance)
First seen2019 (as ABCD); LockBit 5.0 Sept 2025
StatusActive (rebuilt post-takedown)
Rank#5
Victims YTD335
Primary targetsCross-sector, Critical infrastructure, Virtualization (ESXi), Agriculture/Food Production

Overview

LockBit emerged in 2019 (initially "ABCD") and industrialised RaaS at scale before Operation Cronos seized its infrastructure in February 2024. It rebuilt within weeks; LockBit 5.0 was announced on the RAMP forum in September 2025 (the group's six-year anniversary) and a Christmas-themed 5.0 DLS launched December 2025, quickly posting 100+ alleged victims. Active member of the Qilin/LockBit/DragonForce ransomware cartel (formed September 2025), which together with The Gentlemen and Akira accounted for 49.5% of all global ransomware attacks in Q2 2026 per ZeroFox. 163 victims in Q1 2026 (+106% vs Q4 2025, rank #4 globally); estimated 179 victims in May 2026 alone (36% of all May DLS posts per Cybersecurity Dive); 311 confirmed victims YTD as of June 20, 2026 (+87% month-on-month May→June); 335 YTD as of Aug 17, 2026 (~24 new victims in the 8 weeks following (14 in the most recent 30 days per ransomware.live). Notable geographic shift: US share fell from historically 50%+ to 21.2% of Q1 2026 victims, with Italy, Brazil, and Turkey absorbing the balance — deliberate targeting diversification to reduce law-enforcement exposure. July–August 2026 activity: at least 5 new postings in July's first two weeks (ComTRI GmbH/Germany/IT, Gies Dienstleistungen/Germany/facilities, A. Bianchini/Spain/manufacturing, Hotel de la Bourse/France/hospitality, JS Hotels/Spain/hospitality — all 🟥 unverified); last observed activity Aug 20, 2026. Top targeted sectors: Manufacturing (18%), Professional Services (17%), Technology (13%), spanning 68 countries as of Aug 2026.

Tradecraft

  • Cross-platform 5.0 ("ChuongDong"): Windows, Linux and ESXi variants (4 build types released Jan 14, 2026: LB_Black, LB_Linux, LB_ESXi, LB_ChuongDong); randomized 16-character extensions; Russian-language system avoidance.
  • Windows binary: heavy obfuscation/packing, DLL reflection, ETW patching (EtwEventWrite patched in-memory to blind EDR telemetry), security-service termination; payloads reflection-loaded from memory (no disk artifact).
  • Social engineering: impersonating IT/help-desk via Microsoft Teams to push remote-access tools (Quick Assist).
  • ~80% Windows targets, ~20% ESXi/Linux; double-extortion model with dedicated Tor leak portal.
  • Refreshed affiliate incentive model to re-recruit operators post-Operation Cronos disruption.

Notable recent victims

  • Central Romana Corporation (Dominican Republic, agribusiness)
  • Shougang Hierro Perú (mining)
  • DaikyoNishikawa (Japan, automotive parts); Sierra Vista Hospital (US healthcare)
  • Clarinda Regional Health Center (Iowa, USA — healthcare; attack Oct 2025, 24,341 patient records including SSNs; breach notification letters mailed June 2026)
  • ComTRI GmbH (Germany, IT services, July 2026 🟥); Gies Dienstleistungen GmbH (Germany, facilities, July 2026 🟥); JS Hotels (Spain, 10-property hospitality group, July 2026 🟥)

Assessment

A resilient brand that survived a global law-enforcement takedown and rebuilt at scale via its affiliate network. The ESXi focus, ETW blinding, and Teams-based help-desk social engineering are the headline risks. The Qilin/DragonForce/LockBit cartel is operationally confirmed as of Q2 2026 and accounts for ~30% of all global ransomware DLS postings on its own; the DOJ's July 16, 2026 bulletproof-hosting indictment targeting Media Land (used by LockBit, Cl0p, and Play) is the first direct counter-cartel infrastructure action naming LockBit-adjacent operations since Operation Cronos. The deliberate US targeting reduction in Q1 2026 remains operationally notable — spreading geographic risk in response to the February 2024 Operation Cronos and subsequent US/UK/Australian sanctions on named affiliates. As of August 2026, LockBit is posting at a slower pace (~14 new victims in the last 30 days vs. an estimated 179 in May 2026 alone), consistent with affiliate-base attrition following the BPH indictment. Available evidence does not establish that the original pre-Cronos central organization has recovered its former operational tempo; the brand persists primarily as an affiliate franchise. Watch for any renewed affiliate-recruitment push or infrastructure rebuild event.

Sources

🗂️ Attacks & victims

All disclosed victims attributed to this actor, newest first.

July 2026

Jul 20 Adventus LockBit Ransomware · IT services · SG Singapore-based IT company claimed on LockBit DLS July 20; no confirmation from organization · Sources: https://www.ransomware.live/ · https://www.breachsense.com/breaches/
Jul 02 A. Bianchini Ingeniero S.A. LockBit Ransomware · industrial engineering · Spain Spanish industrial engineering company; LockBit DLS claim July 2, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/lockbit · Sources: [ransomware.live]
Jul 02 A. Bianchini LockBit Ransomware · Manufacturing (galvanized steel wire) · Spain Spanish galvanized steel wire manufacturer (abianchini.es, founded 1908) listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://ransomware.live/id/YWJpYW5jaGluaS5lc0Bsb2NrYml0NQ==
Jul 02 JS Hotels LockBit Ransomware · Hospitality · Spain Spanish hospitality group (jshotels.com) operating 10 hotel properties in Majorca; listed on LockBit 5.0 DLS approximately July 2 2026. DLS claim unverified. · Sources: https://www.ransomware.live/id/anNob3RlbHMuY29tQGxvY2tiaXQ1
Jul 01 Gies Dienstleistungen LockBit Ransomware · facility management · Germany German facility management and building services company; LockBit 5.0 DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
Jul 01 ComTRI GmbH LockBit Ransomware · IT Services · Germany German IT services provider listed on LockBit 5.0 DLS approximately July 1 2026. DLS claim unverified by independent source. · Sources: https://www.ransomware.live/
Jul 01 Hotel de la Bourse LockBit Ransomware · Hospitality · France Hotel in Mulhouse, France (hotel-bourse.com) listed on LockBit 5.0 DLS approximately July 1 2026, discovered July 11 2026. DLS claim unverified. · Sources: https://ransomware.live/id/aG90ZWwtYm91cnNlLmNvbUBsb2NrYml0NQ==

June 2026

Jun 20 sierravistahospital.com LockBit Ransomware · healthcare · US Sources: ransomware.live DLS
Jun 19 DaikyoNishikawa Corporation LockBit Ransomware · automotive parts · Japan Sources: ransomware.live DLS
Jun 19 Como Furniture Enterprises Co., Ltd. LockBit Ransomware · manufacturing · Taiwan Sources: ransomware.live DLS
Jun 11 Central Romana Corporation LockBit Ransomware · agribusiness · Dominican Republic Sources: ransomware.live DLS / FalconFeeds
Jun 11 Shougang Hierro Perú S.A.A. LockBit Ransomware · mining · Peru Sources: ransomware.live DLS / FalconFeeds
Jun 11 Stahlwille B.V. LockBit Ransomware · tool manufacturing · Netherlands Sources: ransomware.live DLS / FalconFeeds
Jun 11 JEC Eye Hospitals and Clinics LockBit Ransomware · healthcare · Indonesia Sources: FalconFeeds
Jun 11 Colégio Santo Inácio LockBit Ransomware · education · Brazil Sources: FalconFeeds
Jun 11 LBR Engineering and Consulting LockBit Ransomware · engineering · Brazil Sources: FalconFeeds

← All threat actors · Full victim database →