MITRE ATT&CK G1020

LockBit Ransomware Group

View MITRE Group Page ↗
Aliases: LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green
Official Attribution Source: U.S. Department of Justice (D.N.J.) & NCA Operation Cronos

Key Facts

Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
4
Indicted individuals
Sanctions
1
OFAC designations
  • Attributed Country: Russian Federation.
  • ATT&CK Group Reference: G1020 (LockBit Ransomware Group).
  • Linked to 1 primary court prosecution records.
  • Identified 4 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to LockBit Ransomware Group Technique frequencies extracted from verified indictments for LockBit Ransomware Group. T1486 Data Encrypted for Impact 1 incidents T1567 Exfiltration Over Web Service 1 incidents T1490 Inhibit System Recovery 1 incidents T1190 Exploit Public-Facing Application 1 incidents T1078 Valid Accounts 1 incidents T1047 Windows Management Instrumentation 1 incidents T1562.001 Disable or Modify Tools 1 incidents T1558.003 Kerberoasting 1 incidents
Technique frequencies extracted from verified indictments for LockBit Ransomware Group.
ATT&CK Techniques Mapped to LockBit Ransomware Group
Technique Frequency
T1486 Data Encrypted for Impact 1 incidents
T1567 Exfiltration Over Web Service 1 incidents
T1490 Inhibit System Recovery 1 incidents
T1190 Exploit Public-Facing Application 1 incidents
T1078 Valid Accounts 1 incidents
T1047 Windows Management Instrumentation 1 incidents
T1562.001 Disable or Modify Tools 1 incidents
T1558.003 Kerberoasting 1 incidents

Prosecution Cases Attributed to This Actor

charged 2024-05-07

U.S. v. Khoroshev et al. (LockBit Ransomware Operation)

Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.

9 techniques View case →

Treasury OFAC Sanctions Actions

Dmitry Yuryevich Khoroshev 2024-05-07

Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia.

Official Treasury Press Release ↗
OPERATIONAL DEFENSE

Targeted Defensive Hardening for LockBit Ransomware Group

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.