Back to Ransomware Database
Ransomware Group
lockbit3
LockBit, also recognized as LockBit Black or Lockbit 3.0, is one of the largest Ransomware Groups in the world and has orchestrated extensive cyberattacks across various industries, impacting thousands of organizations globally with its relentless and adaptive strategies.
Known victims2016
Threat Level
CRITICAL
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Gosecretsdump
- LaZagne
- LostMyPassword
- Mimikatz
- NirSoft ExtPassword
- +3 more
DefenseEvasion
- Backstab (Process Explorer driver)
- Defender Control
- GMER
- PCHunter
- PowerTool
- +2 more
DiscoveryEnum
- AdFind
- Advanced IP Scanner
- Advanced Port Scanner
- Bloodhound
- Seatbelt
- +1 more
Exfiltration
- Anonfiles
- FileZilla
- File[.]io
- FreeFileSync
- MEGA
- +7 more
LOLBAS
- BCDEdit
- PsExec
Networking
- Ligolo
- Ngrok
- Plink
Offsec
- Cobalt Strike
- Impacket
- Koadic
- Metasploit
- PowerShell Empire
- +1 more
RMM-Tools
- Action1
- AnyDesk
- FixMeIt
- ScreenConnect
- Splashtop
- +2 more
Indicators of Compromise (IOCs)
IP Addresses
10- 150.171.30.10
- 20.101.57.9
- 84.201.211.40
- 23.54.127.209
- 64.233.181.94
- 199.232.210.172
- 184.28.89.167
- 20.12.23.50
- 184.30.21.171
- 40.69.42.241
Get Complete IOC Feed
Access our full IOC database via API for integration with your SIEM/SOAR.
Get StartedNo credit card required · Free API key
Check If You’re Affected
Search our database to see if your organization appears in lockbit3’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request