LockBit is one of the most prolific ransomware groups in history, operating as a full RaaS platform that at its peak accounted for an estimated 44% of all ransomware incidents globally in 2023, targeting virtually every sector worldwide through an affiliate model where developers maintain infrastructure and affiliates conduct intrusions.
Multi-threaded encryption using AES+RSA
Deletes shadow copies and disables recovery mode
Stops security, database, and backup services
Self-spreading via SMB
Establishes persistence via registry
Disables Windows Defender and EDR