logo

Unpicking LockBit — 22 Cases of Affiliate Tradecraft

ID: 45d44ee8-21b2-57f5-9094-ab093d2ba2cb

STIX ID: report--45d44ee8-21b2-57f5-9094-ab093d2ba2cb

Feed Name: DataBreaches.Net

Threat Score
75/100

Date Published: 2024-02-22

Date Updated: 2026-04-19

Author: Dissent

...
...

Secureworks outlines how the GOLD MYSTIC group operated the LockBit RaaS since 2019, compromising thousands of organizations and employing varied TTPs such as manual and domain controller–driven ransomware deployment, data-theft extortion without encryption, and targeting VMware ESXi environments; it also notes copycats using the LockBit brand. The brief references the Feb 19, 2024 international law-enforcement disruption led by the UK NCA and US FBI against LockBit infrastructure and links to the full Secureworks report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.