ATT&CKSoftwareLockBit 3.0

LockBit 3.0

S1202

Malware.View on attack.mitre.org

About this malware

LockBit 3.0 is an evolution of the LockBit Ransomware-as-a-Service (RaaS) offering with similarities to BlackMatter and BlackCat ransomware. LockBit 3.0 has been in use since at least June 2022 and features enhanced defense evasion and exfiltration tactics, robust encryption methods for Windows and VMware ESXi systems, and a more refined RaaS structure over its predecessors such as LockBit 2.0.

Techniques used34

Procedure examples34

TechniqueProcedure example
T1021.002
SMB/Windows Admin Shares

LockBit 3.0 can use SMB for lateral movement.

T1027.002
Software Packing

LockBit 3.0 can use code packing to hinder analysis.

T1027.013
Encrypted/Encoded File

The LockBit 3.0 payload includes an encrypted main component.

T1057
Process Discovery

LockBit 3.0 can identify and terminate specific services.

T1059.001
PowerShell

LockBit 3.0 can use PowerShell to apply Group Policy changes.

T1070.004
File Deletion

LockBit 3.0 can delete itself from disk.

T1071.001
Web Protocols

LockBit 3.0 can use HTTP to send victim host information to C2.

T1078.003
Local Accounts

LockBit 3.0 can use a compromised local account for lateral movement.

T1082
System Information Discovery

LockBit 3.0 can enumerate system hostname and domain.

T1083
File and Directory Discovery

LockBit 3.0 can exclude files associated with core system functions from encryption.

T1106
Native API

LockBit 3.0 has the ability to directly call native Windows API items during execution.

T1112
Modify Registry

LockBit 3.0 can change the Registry values for Group Policy refresh time, to disable SmartScreen, and to disable Windows Defender.

T1120
Peripheral Device Discovery

LockBit 3.0 has the ability to discover external storage devices.

T1132.001
Standard Encoding

LockBit 3.0 can Base64-encode C2 communication.

T1135
Network Share Discovery

LockBit 3.0 can identify network shares on compromised systems.

View all 34 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References4

  1. INCIBE-CERT LockBit MAR 2024 Open source
    INCIBE-CERT. (2024, March 14). LockBit: response and recovery actions. Retrieved February 5, 2025.
  2. Joint Cybersecurity Advisory LockBit 3.0 MAR 2023 Open source
    FBI et al. (2023, March 16). #StopRansomware: LockBit 3.0. Retrieved February 5, 2025.
  3. Joint Cybersecurity Advisory LockBit JUN 2023 Open source
    CISA et al. (2023, June 14). UNDERSTANDING RANSOMWARE THREAT ACTORS: LOCKBIT. Retrieved February 5, 2025.
  4. Sentinel Labs LockBit 3.0 JUL 2022 Open source
    Walter, J. (2022, July 21). LockBit 3.0 Update | Unpicking the Ransomware’s Latest Anti-Analysis and Evasion Techniques. Retrieved February 5, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.