Avatier

Threat actor

LockBit

CISA and international partners describe LockBit as a ransomware-as-a-service operation that recruits affiliates to carry out ransomware attacks using its tools and infrastructure.Source [1]

What authorities and investigators report

  • The advisory says that since January 2020, affiliates using LockBit attacked organizations across critical infrastructure sectors including financial services, education, energy, healthcare, manufacturing and transportation.Source [1]
  • It says LockBit affiliates used phishing and spearphishing, and obtained and abused credentials of existing accounts, to gain initial access.Source [1]
  • It says that since 2021, LockBit affiliates have used double extortion, encrypting victim data and exfiltrating it while threatening to post it on leak sites.Source [1]
  • The U.S. Treasury said LockBit licenses its ransomware to affiliated cybercriminals in exchange for payment, including a percentage of paid ransoms.Source [2]
  • Treasury, citing the Justice Department, said LockBit has targeted over 2,500 victims worldwide and is alleged to have received more than $500 million in ransom payments.Source [2]

Individuals named in government actions

Status is as stated in the cited government document on its date.

  • Dmitry Yuryevich Khoroshev — sanctionedSource [2]

Techniques

Attack vectors

Sources

  1. Understanding Ransomware Threat Actors: LockBit (AA23-165A) — CISA, 2023-06-14
  2. United States Sanctions Senior Leader of the LockBit Ransomware Group (jy2326) — U.S. Department of the Treasury, 2024-05-07

Last reviewed Oct 2, 2026