ATT&CKSoftwareLockBit 2.0

LockBit 2.0

S1199

Malware.View on attack.mitre.org

About this malware

LockBit 2.0 is an affiliate-based Ransomware-as-a-Service (RaaS) that has been in use since at least June 2021 as the successor to LockBit Ransomware. LockBit 2.0 has versions capable of infecting Windows and VMware ESXi virtual machines, and has been observed targeting multiple industry verticals globally.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

LockBit 2.0 has the ability to move laterally via SMB.

T1047
Windows Management Instrumentation

LockBit 2.0 can use wmic.exe to delete volume shadow copies.

T1053.005
Scheduled Task

LockBit 2.0 can be executed via scheduled task.

T1057
Process Discovery

LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration.

T1059.001
PowerShell

LockBit 2.0 can use the PowerShell module `InvokeGPUpdate` to modify Group Policy.

T1059.003
Windows Command Shell

LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.

T1070.004
File Deletion

LockBit 2.0 can delete itself from disk after execution.

T1082
System Information Discovery

LockBit 2.0 can enumerate system information including hostname and domain information.

T1083
File and Directory Discovery

LockBit 2.0 can exclude files associated with core system functions from encryption.

T1112
Modify Registry

LockBit 2.0 can create Registry keys to bypass UAC and for persistence.

T1120
Peripheral Device Discovery

LockBit 2.0 has the ability to identify mounted external storage devices.

T1135
Network Share Discovery

LockBit 2.0 can discover remote shares.

T1136
Create Account

LockBit 2.0 has been observed creating accounts for persistence using simple names like "a".

T1140
Deobfuscate/Decode Files or Information

LockBit 2.0 can decode scripts and strings in loaded modules.

T1480
Execution Guardrails

LockBit 2.0 will not execute on hosts where the system language is set to a language spoken in the Commonwealth of Independent States region.

View all 26 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. FBI Lockbit 2.0 FEB 2022 Open source
    FBI. (2022, February 4). Indicators of Compromise Associated with LockBit 2.0 Ransomware. Retrieved January 24, 2025.
  2. Palo Alto Lockbit 2.0 JUN 2022 Open source
    Elsad, A. et al. (2022, June 9). LockBit 2.0: How This RaaS Operates and How to Protect Against It. Retrieved January 24, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.