LockBit 3.0 (LockBit Black) is a global Ransomware-as-a-Service group known for modular encrypted payloads and code reuse from BlackMatter.
Analyst brief
LockBit 3.0 (LockBit Black) is a criminal Ransomware-as-a-Service group active since June 2022. It targets all sectors globally, focusing on Windows and VMware ESXi environments. Key TTPs include modular encrypted payloads designed to evade analysis and code reuse from BlackMatter ransomware. Defenders should monitor for suspicious PowerShell scripts, unusual service creation attempts, and brute-force attacks against ESXi servers.
lockbit3_fs
crime
LockBit 3.0 ("LockBit Black"), active since June 2022, is the third iteration of the LockBit RaaS platform incorporating code from BlackMatter ransomware, featuring modular encrypted payloads that evade analysis and targeting Windows and VMware ESXi environments across all sectors globally.