Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ LockBit

🇷🇺LockBit

🇷🇺 LockBit is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 14 detection use cases to this actor across 35 MITRE ATT&CK techniques, with 4 threat-intel articles citing them. Active in our corpus from 2025-12-11 to 2026-04-20.

crit 3high 1
View full actor card → All threat actors
14Use cases
4Articles
35Techniques
0IOCs

Known aliases

LockBitLockBit 2.0LockBit 3.0LockBit BlackLockBit GreenLockBit 5.0

Top techniques

All other tracked techniques

Detection use cases (14)

LockBit (BITWISE SPIDER) pre-encryption inhibit-recovery command chain AI · profile SΣ LockBit affiliate Rclone-to-MEGA / StealBit double-extortion exfiltration AI · profile SΣ Phishing-link click correlated to endpoint execution Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal Trusted vendor binary / installer launching unusual children Internal BYOVD: Genshin Impact mhyprot.sys driver dropped/loaded outside legitimate game install (Embargo evil-mhyprot-cli) Bespoke EDRSilencer-style WFP filter blocking outbound traffic from named EDR binaries Bespoke EDR-Freeze: WerFaultSecure.exe abused to suspend AV/EDR processes via MiniDumpWriteDump race Bespoke Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal

Threat-intel articles (4)