logo

A Deep-dive Analysis of LOCKBIT 2.0

ID: b507f826-98a3-551b-ab6c-627fd2cfeeeb

STIX ID: report--b507f826-98a3-551b-ab6c-627fd2cfeeeb

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2021-08-16

Date Updated: 2026-07-20

...
...

LOCKBIT 2.0 is a Ransomware-as-a-Service (RaaS) operation that performs double extortion by exfiltrating victim data (using tools such as StealBIT) and then encrypting files with a .lockbit extension; affiliates deploy customized variants and use Cobalt Strike, Metasploit, AD/LDAP enumeration, service termination, Defender policy modification, process injection, and VMware shared-folder propagation. The report provides static and dynamic analysis of a Windows x86 sample, describes victim-facing artifacts (ransom notes, desktop changes, TOR leak site), lists targeted/terminated services and a SHA-256 indicator, and offers defensive recommendations such as MFA, updates, AV, and offline backups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.