logo

Alleged Builder of LockBit Black Ransomware Leaked

ID: d3ea5a8a-d222-5500-b1f4-843f329382d6

STIX ID: report--d3ea5a8a-d222-5500-b1f4-843f329382d6

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-21

Date Updated: 2026-07-16

...
...

The report describes a newly created Twitter account that leaked an alleged LockBit 3.0 (LockBit Black) ransomware builder; analysis of the leaked archive shows a batch-driven builder (Build.bat → keygen.exe and builder.exe), a configurable config.json (encryption modes, exclusion lists, language checks, ransom note), and generated payloads that successfully encrypted and decrypted files. The authors warn the leak could enable new threat actors, outline the risk, and provide recommended mitigations such as secure backups, MFA, vulnerability management, user awareness, and darkweb monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.