🇷🇺LockBit
🇷🇺 LockBit is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 12 detection use cases to this actor across 50 MITRE ATT&CK techniques, with 6 threat-intel articles citing them. Active in our corpus from 2025-12-11 to 2026-08-13.
crit 5high 1
12Use cases
6Articles
50Techniques
14IOCs
Known aliases
LockBitLockBit 2.0LockBit 3.0LockBit BlackLockBit GreenLockBit 5.0
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1014 · RootkitT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.002 · Software PackingT1027.005 · Indicator Removal from ToolsT1027.009 · Embedded PayloadsT1037.001 · Logon Script (Windows)T1052.001 · Exfiltration over USBT1055 · Process InjectionT1056.001 · KeyloggingT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.004 · DNST1112 · Modify RegistryT1133 · External Remote ServicesT1134.001 · Token Impersonation/TheftT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1195.002 · Compromise Software Supply ChainT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1489 · Service StopT1490 · Inhibit System RecoveryT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1555.003 · Credentials from Web BrowsersT1562.001 · T1562.001T1562.004 · T1562.004T1562.006 · T1562.006T1562.009 · T1562.009T1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1574.001 · DLLT1586 · Compromise Accounts
Detection use cases (12)
Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Suspicious browser extension installation Infostealer — non-browser process accessing browser cookie/login DBs Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Ransomware-style mass file rename / extension change LSASS process access / dump (credential theft) Remote service execution — PsExec / SMB lateral movementThreat-intel articles (6)
crit ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories · 2026-08-13
crit What the ransom note won’t say · 2026-04-20
crit EDR killers explained: Beyond the drivers · 2026-03-19
Tracked indicators
Domains (13)
ccleanerwind.top city-forum.com thu-ipad-02.cfd thu-ipad-03.cfd thu-ipad-04.cfd thu-ipad-05.cfd thu-ipad-06.cfd thu-ipad-07.cfd thu-ipad-08.cfd thu-ipad-09.cfd thu-ipad-10.cfd thu-ipad-11.cfd thu-ipad-12.cfdIP addresses (1)
158.220.87.79CVEs (1)
CVE-2026-20685