Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ LockBit

🇷🇺LockBit

🇷🇺 LockBit is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: Criminal. We map 12 detection use cases to this actor across 50 MITRE ATT&CK techniques, with 6 threat-intel articles citing them. Active in our corpus from 2025-12-11 to 2026-08-13.

crit 5high 1
View full actor card → All threat actors
12Use cases
6Articles
50Techniques
14IOCs

Known aliases

LockBitLockBit 2.0LockBit 3.0LockBit BlackLockBit GreenLockBit 5.0

Top techniques

All other tracked techniques

Detection use cases (12)

Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Asset exposure — vulnerability matches article CVE(s) Internal Phishing-link click correlated to endpoint execution Internal Email attachment opened from external sender Internal Office app spawning script/LOLBin child process Internal Fake CAPTCHA / clipboard-injected PowerShell (ClickFix / FakeCaptcha) Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal Remote service execution — PsExec / SMB lateral movement Internal

Threat-intel articles (6)

Tracked indicators

Domains (13)

ccleanerwind.top city-forum.com thu-ipad-02.cfd thu-ipad-03.cfd thu-ipad-04.cfd thu-ipad-05.cfd thu-ipad-06.cfd thu-ipad-07.cfd thu-ipad-08.cfd thu-ipad-09.cfd thu-ipad-10.cfd thu-ipad-11.cfd thu-ipad-12.cfd

IP addresses (1)

158.220.87.79

CVEs (1)

CVE-2026-20685