LockBit Ransomware Group
View MITRE Group Page ↗Key Facts
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G1020 (LockBit Ransomware Group).
- Linked to 1 primary court prosecution records.
- Identified 4 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1486 Data Encrypted for Impact | 1 incidents |
| T1567 Exfiltration Over Web Service | 1 incidents |
| T1490 Inhibit System Recovery | 1 incidents |
| T1190 Exploit Public-Facing Application | 1 incidents |
| T1078 Valid Accounts | 1 incidents |
| T1047 Windows Management Instrumentation | 1 incidents |
| T1562.001 Disable or Modify Tools | 1 incidents |
| T1558.003 Kerberoasting | 1 incidents |
Prosecution Cases Attributed to This Actor
U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.
Treasury OFAC Sanctions Actions
Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia.
Official Treasury Press Release ↗Targeted Defensive Hardening for LockBit Ransomware Group
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.