Uptime Hamster: 21d 12h 17mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza lockbit

lockbit

1 incidentes 0 paises 0 sectores threat-actor RU Ultimo: 2026-06-29
Aliases: lockbit3, ABCD ransomware, lockbit5, lockbit, Babuk, Conti, LockBit 3, HeaderTip, cosmicbeetle, scarab, spacecolon
Ver en IntelTracker → APTTrail →
Lockbit is a financially motivated cybercriminal organization that emerged in September 2019 as 'ABCD ransomware' and operates a highly prolific ransomware-as-a-service (RaaS) model. It evolved through several iterations, including Lockbit 2.0 (also known as Lockbit Red), Lockbit 3.0 (Lockbit Black), Lockbit Green, Lockbit-NG-Dev (Lockbit 4?), and Lockbit 5.0, consistently enhancing its speed, automation, and platform targeting capabilities. While government agencies have not formally attributed the group to a specific nation-state, it is believed with moderate confidence to operate primarily out of Russia and other former Commonwealth of Independent States countries, intentionally avoiding attacks within those regions to evade prosecution. Lockbit distinguishes itself by its rapid encryption capabilities, automated spread mechanism, and its pioneering adoption and refinement of double and triple extortion tactics, which include data encryption, public data leaks, and distributed denia

Aliases del actor

lockbit3ABCD ransomwarelockbit5lockbitBabukContiLockBit 3HeaderTipcosmicbeetlescarabspacecolon

Actores similares

lockbit3ransomware · 2016lockbit5ransomware · 278lockbit2ransomware · 1002lockbit3_fsthreat-actor · 2lockbit4threat-actor · 0LockBit 5.0threat-actor · 0contiransomware · 351babuk2ransomware · 180 Babuk-Lockerransomware · 0babuk-bjorkaransomware · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownduckduckgo.comApache ActiveMQ Exploit Leads to LockBit Ransomware
DLS / leak siteunknownduckduckgo.comApache ActiveMQ Exploit Leads to LockBit Ransomware
DLS / leak siteseizedransomware.anggipradana.comRansomware Group: lockbit5
DLS / leak siteunknownnitter.netIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
X/Twitterunknownx.comIdo Cohen: Tracking the pulse of ransomware in 2026—these are the groups leading the global attack landscape right now: Qilin – 665 attacks The Gentleman – 453 attacks Akira – 290 attacks DragonForce – 245 attacks INC – 239 attacks Lockbit – 199 attacks Play – 154 attacks CLOP – 127 attacks NightSpire – 115 attacks CoinBase Cartel – 97 attacks Stay ahead of ransomware threats.
Repositoriounknowngithub.comLockBit
DLS / leak siteunknownraw.githubusercontent.comLockBit
DLS / leak siteunknowndoublepulsar.comLockBit
DLS / leak siteunknownwww.cisa.govLockBit
X/Twitterunknowntwitter.comLockBit
DLS / onionuplockbitaptq7ephv2oigdncfhtwhpqgwmqojnxqdyhprxxfpcllqdxad.onionlockbit2
DLS / onionuplockbitaptstzf3er2lz6ku3xuifafq2yh5lmiqj5ncur6rtlmkteiqd.onionlockbit2
DLS / onionunknownlockbit7z2jwcskxpbokpemdxmltipntwlkmidcll2qirbu7ykg46eyd.onionlockbit3_fs
DLS / onionunknownlockbit7z2mmiz3ryxafn5kapbvbbiywsxwovasfkgf5dqqp5kxlajad.onionlockbit3_fs
DLS / onionunknownlockbitfss2w7co3ij6am6wox4xcurtgwukunx3yubcoe5cbxiqakxqd.onionLockBit Onion: lockbitfss2w7co3ij6am6wox4xcur...
DLS / onionunknownlockbitfsvf75glg226he5inkfgtuoakt4vgfhd7nfgghx5kwz5zo3ad.onionLockBit Onion: lockbitfsvf75glg226he5inkfgtuo...
DLS / onionunknownlockbitfskq2fxclyfrop5yizyxpzu65w7pphsgthawcyb4gd27x62id.onionLockBit Onion: lockbitfskq2fxclyfrop5yizyxpzu...
DLS / onionunknownlockbitpn4nmflibn4cooh4sydie6bpoy33tbxa3rjebryxc5vblkwyd.onionLockBit Onion: lockbitpn4nmflibn4cooh4sydie6b...
DLS / onionunknownlockbitpntsng25yxacx5jqdccvoqd5qtyzzximljfskvtk6ektjhvad.onionLockBit Onion: lockbitpntsng25yxacx5jqdccvoqd...
DLS / onionunknownlockbitpn7doehfdzu3r2orcibdx6njq62aavkr4hgh3p6rednr5gfad.onionLockBit Onion: lockbitpn7doehfdzu3r2orcibdx6n...
DLS / leak siteunknownwww.breachsense.comseiei-ashd.co.jp - LockBit Data Breach
DLS / leak siteunknowngetbootstrap.comtntorello.com - LockBit Data Breach
Repositoriounknowngithub.comtntorello.com - LockBit Data Breach
Repositoriounknowngithub.comtntorello.com - LockBit Data Breach
DLS / onionofflinelockbitkodidilol.onionCTI.FYI
Malware asociado
win.webmonitor, NetSupport, WannaCry, win.nymaim, Agent Tesla, Qbot
Tecnicas MITRE
T1003, T1008, T1038, T1102, T1059.003, TA0034
CVEs relacionadas
CVE-2025-61984, CVE-2025-61882, CVE-2025-49844, CVE-2025-42706, CVE-2025-42701, CVE-2025-37947
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises objetivo (OSINT)

United Arab EmiratesAfghanistanAlbaniaArmeniaAngolaArgentinaAustriaAustraliaBosnia and HerzegovinaBarbados

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesRail TransportationSoftware PublishersReal EstateRental and Leasing ServicesHospitalsEnterprises & HoldingAccommodation

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com github.com raw.githubusercontent.com