{"id":41397,"date":"2021-06-18T10:48:33","date_gmt":"2021-06-18T10:48:33","guid":{"rendered":"http:\/\/a8681678-8c2c-4fad-b895-177f5210f231"},"modified":"2021-06-18T10:48:33","modified_gmt":"2021-06-18T10:48:33","slug":"a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","title":{"rendered":"A deep dive into the operations of the LockBit ransomware group"},"content":{"rendered":"<p>Researchers have provided an in-depth look at how LockBit, one of the newer ransomware groups on the scene, operates.<\/p>\n<p>Ransomware has become one of the most <a href=\"https:\/\/www.zdnet.com\/article\/ransomware-is-the-key-online-cybersecurity-threat-to-people-and-businesses-warns-cyber-chief\/\" target=\"_blank\" rel=\"noopener\">disruptive forms<\/a> of cyberattack this year. It was back in 2017 with the global <a href=\"https:\/\/www.zdnet.com\/article\/wannacry-ransomware-is-still-infecting-pcs-and-some-victims-are-still-trying-to-pay-the-ransom\/\" target=\"_blank\" rel=\"noopener\">WannaCry outbreak<\/a> that we first saw the severe disruption the malware could cause, and in 2021, nothing seems to have changed for the better.&nbsp;<\/p>\n<p>This year alone, so far we&#8217;ve seen the <a href=\"https:\/\/www.zdnet.com\/article\/colonial-pipeline-ransomware-attack-everything-you-need-to-know\/\" target=\"_blank\" rel=\"noopener\">Colonial Pipeline<\/a> ransomware disaster that caused fuel supply shortages across parts of the US; ongoing issues at Ireland&#8217;s <a href=\"https:\/\/www.zdnet.com\/article\/ransomware-irelands-health-service-is-still-significantly-disrupted-weeks-after-attack\/\" target=\"_blank\" rel=\"noopener\">national health service<\/a>, and systematic disruption for meat processor giant JBS due to the malware. <\/p>\n<p>Ransomware operators will deploy malware able to encrypt and lock systems, and they may also steal confidential data during an attack. Payment is then demanded in return for a decryption key.&nbsp; <\/p>\n<p>Losing money by the second while their systems fail to respond, victim enterprise players may then be subject to a second salvo designed to pile on the pressure &#8212; the threat of corporate data being either leaked or sold online through so-called leak sites in the dark web.&nbsp; <\/p>\n<p>Ransomware attacks are projected to cost <a href=\"https:\/\/www.zdnet.com\/article\/the-cost-of-ransomware-around-the-globe-to-go-beyond-265-billion-in-the-next-decade\/\" target=\"_blank\" rel=\"noopener\">$265 billion worldwide<\/a> by 2031, and payouts now commonly reach millions of dollars &#8212; such as in <a href=\"https:\/\/www.zdnet.com\/article\/ransomware-meat-firm-jbs-says-it-paid-out-11m-after-attack\/\" target=\"_blank\" rel=\"noopener\">the case of JBS<\/a>. However, there is no guarantee that decryption keys are fit for purpose or that paying once means that an organization will not be hit again.&nbsp; <\/p>\n<p>A Cybereason survey <a href=\"https:\/\/www.zdnet.com\/article\/most-firms-face-second-ransomware-attack-after-paying-off-first\/\" target=\"_blank\" rel=\"noopener\">released this week<\/a> suggested that up to 80% of businesses who fell prey to ransomware and paid up have experienced a second attack &#8212; potentially by the same threat actors.&nbsp; <\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_zd_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\"> <\/section>\n<p>The threat of ransomware to businesses and critical utilities has become serious enough that the issue was raised <a href=\"https:\/\/www.zdnet.com\/article\/biden-and-putin-spar-over-cybersecurity-ransomware-at-geneva-summit\/\" target=\"_blank\" rel=\"noopener\">during a meeting<\/a> between US President Joe Biden and Russian President Vladimir Putin at the Geneva summit. &nbsp; <\/p>\n<p>Each group has a different modus operandi and ransomware operators are constantly &#8216;retiring&#8217; or joining the fold, often through a Ransomware-as-a-Service (RaaS) affiliate model.&nbsp; <\/p>\n<p>On Friday, the Prodaft Threat Intelligence (PTI) team <a href=\"https:\/\/www.prodaft.com\/m\/reports\/LockBit_Case_Report___TLPWHITE.pdf\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">published a report<\/a> (.PDF) exploring LockBit and its affiliates.&nbsp; <\/p>\n<p>According to the research, LockBit, believed to have previously operated under the name ABCD, operates a RaaS structure that provides affiliate groups a central control panel to create new LockBit samples, manage their victims, publish blog posts, and also pull up statistics concerning the success &#8212; or failure &#8212; of their attack attempts.&nbsp; <\/p>\n<p>The investigation revealed that LockBit affiliates most often will buy Remote Desktop Protocol (RDP) access to servers as an initial attack vector, although they may also use typical phishing and credential stuffing techniques.&nbsp; <\/p>\n<p>&#8220;Those kinds of tailored access services can be purchased as low as $5, thus mak[ing] this approach very lucrative for affiliates,&#8221; Prodaft notes.&nbsp; <\/p>\n<p>Exploits, too, are used to compromise vulnerable systems, including Fortinet VPN vulnerabilities that have not been patched on target machines.&nbsp; <\/p>\n<p>Forensic investigations of machines attacked by LockBit affiliates show that threat groups will often first try to identify &#8220;mission-critical&#8221; systems including NAS devices, backup servers, and domain controllers. Data exfiltration then begins and packages are usually uploaded to services including MEGA&#8217;s cloud storage platform.&nbsp; <\/p>\n<p>A LockBit sample is then deployed manually and files are encrypted with a generated AES key. Backups are deleted and the system wallpaper is changed to a ransom note containing a link to a .onion website address to purchase decryption software.&nbsp; <\/p>\n<p>The website also offers a decryption &#8216;trial,&#8217; in which one file &#8212; with a size smaller than 256KB &#8212; can be decrypted for free.&nbsp; <\/p>\n<p>However, this isn&#8217;t just to show that decryption is possible. An encrypted file needs to be submitted for affiliates to generate a decryptor for that particular victim.&nbsp; <\/p>\n<p>If victims reach out, attackers can open a chat window in the LockBit panel to talk to them. Conversations will often start with the ransom demand, payment deadline, method &#8212; usually in Bitcoin (BTC) &#8212; and instructions on how to purchase cryptocurrency.&nbsp; <\/p>\n<p>Prodaft was able to obtain access to the LockBit panel, revealing affiliate usernames, the number of victims, registration dates, and contact details.&nbsp; <\/p>\n<figure class=\"image image-original shortcode-image\"><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/\" class=\"lazy\" alt=\"screenshot-2021-06-17-at-15-13-54.png\" height=\"auto\" width=\"1200\" data-original=\"https:\/\/www.zdnet.com\/a\/hub\/i\/r\/2021\/06\/17\/048eb33d-bb36-431c-83c1-ee71b003a924\/resize\/1200xauto\/dbc505a8a9e6aa2220e4a35d2d97c386\/screenshot-2021-06-17-at-15-13-54.png\"><\/span><noscript><span class=\"img aspect-set \"><img decoding=\"async\" src=\"https:\/\/www.zdnet.com\/a\/hub\/i\/r\/2021\/06\/17\/048eb33d-bb36-431c-83c1-ee71b003a924\/resize\/1200xauto\/dbc505a8a9e6aa2220e4a35d2d97c386\/screenshot-2021-06-17-at-15-13-54.png\" class alt=\"screenshot-2021-06-17-at-15-13-54.png\" height=\"auto\" width=\"1200\"><\/span><\/noscript><figcaption><span class=\"caption\"><\/span><span class=\"credit\"> Prodaft <\/span><\/figcaption><\/figure>\n<p>The research team says that clues within the affiliate names and addresses suggest that some may also be signed up with Babuk and REvil, two other RaaS groups &#8212; however, the investigation is ongoing.&nbsp;<\/p>\n<p>On average, LockBit affiliates request roughly $85,000 from each victim, 10 &#8211; 30% of which goes to the RaaS operators, and the ransomware has infected thousands of devices worldwide. Over 20% of victims on the dashboard were in the software and services sector.&nbsp; <\/p>\n<p>&#8220;Commercial and professional services as well as the transportation sector also highly targeted by the LockBit group,&#8221; Prodaft says. &#8220;However, it should be noted that the value of the ransom is determined by the affiliate after various checks using online services. This value does not solely depend on the sector of the victim.&#8221; <\/p>\n<p>At the time of writing, LockBit&#8217;s leak site was unavailable. After infiltrating LockBit&#8217;s systems, the researchers decrypted all of the accessible victims on the platform.<\/p>\n<p>Earlier this month, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/ransomware-gangs-team-up-to-form-extortion-cartel\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-component=\"externalLink\">Bleeping Computer<\/a> reported that LockBit was a new entrant to a ransomware cartel overseen by Maze. Prodaft told ZDNet that as they &#8220;detected several LockBit affiliates are also working for other ransomware groups, collaboration is very likely.&#8221;<\/p>\n<h3> Previous and related coverage <\/h3>\n<hr>\n<p><strong>Have a tip?<\/strong> Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0<\/p>\n<hr>\n<p> READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most victims are from the enterprise and are expected to pay an average ransom of $85,000.<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-41397","post","type-post","status-publish","format-standard","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>A deep dive into the operations of the LockBit ransomware group 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A deep dive into the operations of the LockBit ransomware group 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-18T10:48:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"A deep dive into the operations of the LockBit ransomware group\",\"datePublished\":\"2021-06-18T10:48:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\"},\"wordCount\":921,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\",\"name\":\"A deep dive into the operations of the LockBit ransomware group 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\",\"datePublished\":\"2021-06-18T10:48:33+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\",\"contentUrl\":\"https:\\\/\\\/www.zdnet.com\\\/article\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A deep dive into the operations of the LockBit ransomware group\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A deep dive into the operations of the LockBit ransomware group 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","og_locale":"en_US","og_type":"article","og_title":"A deep dive into the operations of the LockBit ransomware group 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-06-18T10:48:33+00:00","og_image":[{"url":"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"A deep dive into the operations of the LockBit ransomware group","datePublished":"2021-06-18T10:48:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/"},"wordCount":921,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","url":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","name":"A deep dive into the operations of the LockBit ransomware group 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#primaryimage"},"thumbnailUrl":"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","datePublished":"2021-06-18T10:48:33+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#primaryimage","url":"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/","contentUrl":"https:\/\/www.zdnet.com\/article\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/a-deep-dive-into-the-operations-of-the-lockbit-ransomware-group\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"A deep dive into the operations of the LockBit ransomware group"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41397"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41397\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}