LockBit 3.0, also known as LockBit Black, is a ransomware-as-a-service (RaaS) variant first observed in June 2022 and operated by the Russian-speaking threat group tracked as LockBitSupp. It belongs to the ransomware category and is the third major version of the LockBit family, succeeding LockBit 2.0.
LockBit 3.0 propagates via multiple methods including phishing emails with malicious attachments, exploitation of unpatched vulnerabilities (e.g., CVE-2021-34527 in Microsoft Exchange), and leveraging compromised credentials for remote desktop protocol (RDP) access. It uses a custom encryptor written in C++ that implements file encryption with AES-256 and RSA-4096, and includes a built-in service to delete Volume Shadow Copies (VSS). Command-and-control (C2) infrastructure relies on a decentralized model using bulletproof hosting and Tor hidden services; encrypted communication is established via HTTPS with custom TLS fingerprints. Persistence is achieved through registry run keys, scheduled tasks, and service installation. Evasion techniques include disabling Windows Defender, bypassing User Account Control (UAC), and using process hollowing to avoid detection by endpoint security tools.
First publicly documented by the Cybersecurity and Infrastructure Security Agency (CISA) in July 2022, LockBit 3.0 was involved in high-profile attacks against Accenture (August 2021 for earlier version, but later incidents include the 2022 attack on the City of Oakland and the 2023 breach of the Royal Mail. On February 19, 2024, international law enforcement agencies under Operation Cronos seized LockBit’s infrastructure and released decryption tools, though the group quickly announced a new version. Notable CVEs exploited include CVE-2023-27350 for PaperCut vulnerabilities and CVE-2023-46604 for Apache ActiveMQ.
Known hashes include SHA256 0f6e4c5a... (example from CISA advisory); behavioral signatures include file extensions appended with .lockbit and ransom notes named README.txt. Network IOCs include communications to Tor onion domains (e.g., lockbitnews5ezd...onion), User-Agent strings like Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 used in C2 beaconing, and mutex names such as GlobalLockBit_3.0_Mutex. Registry artifacts include keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with values referencing lockbit.exe.
LockBit 3.0 exfiltrates sensitive data using a custom data-stealing tool called StealBit before encryption, then threatens to publish it on a dedicated leak site (DLS) to pressure victims. Financial losses from LockBit 3.0 attacks total over $500 million globally (per FBI estimates), with the manufacturing, healthcare, and energy sectors most frequently targeted. For example, the 2023 attack on the City of Oakland disrupted municipal services for weeks and resulted in $10 million in recovery costs.
Mitigation measures include applying patches for known CVEs (e.g., CVE-2023-27350), enforcing multifactor authentication on RDP, implementing network segmentation, and deploying endpoint detection and response (EDR) tools with rules for process hollowing and VSS deletion. CISA recommends using the LockBit 3.0 detection rules provided in its joint advisory (AA23-165A) and maintaining offline backups. For specific IOCs and YARA rules, refer to MITRE ATT&CK technique T1486 (Data Encrypted for Impact) and the LockBit 3.0 profile on the MITRE ATT&CK knowledge base.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.