LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions.
LockBit primarily uses TTPs such as its RaaS platform, double extortion (data theft and encryption), supply chain attacks, as well as custom tools and vulnerabilities for initial access and lateral movement.
What defense strategies are recommended against the LockBit group?+
Defenders must focus on enhanced monitoring for unauthorized access and unusual data exfiltration, rigorous patch management, and deploying layered defenses to detect intrusions before the encryption stage.