MITRE ATT&CK G1020
LockBit Ransomware Group
View MITRE Group Page ↗
Aliases: LockBit 2.0, LockBit 3.0, LockBit Black, LockBit Green
Official Attribution Source: U.S. Department of Justice (D.N.J.) & NCA Operation Cronos
Key Facts
Jurisdiction
Russian Federation
Geographic origin
Cases
1
Prosecution matters
Defendants
4
Indicted individuals
Sanctions
1
OFAC designations
- Attributed Country: Russian Federation.
- ATT&CK Group Reference: G1020 (LockBit Ransomware Group).
- Linked to 1 primary court prosecution records.
- Identified 4 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1486 Data Encrypted for Impact | 1 incidents |
| T1567 Exfiltration Over Web Service | 1 incidents |
| T1490 Inhibit System Recovery | 1 incidents |
| T1190 Exploit Public-Facing Application | 1 incidents |
| T1078 Valid Accounts | 1 incidents |
| T1047 Windows Management Instrumentation | 1 incidents |
| T1562.001 Disable or Modify Tools | 1 incidents |
| T1558.003 Kerberoasting | 1 incidents |
Prosecution Cases Attributed to This Actor
charged 2024-05-07
U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.
9 techniques
View case →
Treasury OFAC Sanctions Actions
Dmitry Yuryevich Khoroshev 2024-05-07
Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia.
Official Treasury Press Release ↗