Skip to main content
Back to Ransomware Database
Ransomware Group

lockbit3

LockBit, also recognized as LockBit Black or Lockbit 3.0, is one of the largest Ransomware Groups in the world and has orchestrated extensive cyberattacks across various industries, impacting thousands of organizations globally with its relentless and adaptive strategies.

Known victims2016

Threat Level

CRITICAL

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Gosecretsdump
  • LaZagne
  • LostMyPassword
  • Mimikatz
  • NirSoft ExtPassword
  • +3 more

DefenseEvasion

  • Backstab (Process Explorer driver)
  • Defender Control
  • GMER
  • PCHunter
  • PowerTool
  • +2 more

DiscoveryEnum

  • AdFind
  • Advanced IP Scanner
  • Advanced Port Scanner
  • Bloodhound
  • Seatbelt
  • +1 more

Exfiltration

  • Anonfiles
  • FileZilla
  • File[.]io
  • FreeFileSync
  • MEGA
  • +7 more

LOLBAS

  • BCDEdit
  • PsExec

Networking

  • Ligolo
  • Ngrok
  • Plink

Offsec

  • Cobalt Strike
  • Impacket
  • Koadic
  • Metasploit
  • PowerShell Empire
  • +1 more

RMM-Tools

  • Action1
  • AnyDesk
  • FixMeIt
  • ScreenConnect
  • Splashtop
  • +2 more

Indicators of Compromise (IOCs)

IP Addresses

10
  • 150.171.30.10
  • 20.101.57.9
  • 84.201.211.40
  • 23.54.127.209
  • 64.233.181.94
  • 199.232.210.172
  • 184.28.89.167
  • 20.12.23.50
  • 184.30.21.171
  • 40.69.42.241

Get Complete IOC Feed

Access our full IOC database via API for integration with your SIEM/SOAR.

Get Started

No credit card required · Free API key

0

Check If You’re Affected

Search our database to see if your organization appears in lockbit3’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request