All threat actors

Threat actor profile

LockBit

Russia-based · GlobalRansomware-as-a-service; data theft and double extortionUpdated

LockBit has run a ransomware-as-a-service programme since September 2019, renting its encryptor and leak site to affiliates in return for a cut of ransoms. US prosecutors say it hit more than 2,500 victims in at least 120 countries and extracted at least $500 million. The UK National Crime Agency described it as the most impactful ransomware group globally before Operation Cronos seized its administration environment, leak site and source code in February 2024. Russian national Dmitry Khoroshev, alleged to be the administrator 'LockBitSupp', was charged and sanctioned in May 2024.

LatestLockBit announced version 5.0 in September 2025, with Windows, Linux and ESXi builds, and launched a new leak site in early December 2025; by January 2026 Arete counted more than 100 alleged victims posted there. Khoroshev remains at large, with a US reward of up to $10 million outstanding.

Timeline

  1. LockBit began operating as a ransomware-as-a-service programme in September 2019, according to US prosecutors.

    US DOJ — U.S. charges Russian national with developing and operating LockBit ransomware (7 May 2024)

  2. Operation Cronos: the NCA-led taskforce took control of LockBit's administration environment and leak site, with arrests in Poland and Ukraine and more than 200 crypto accounts frozen.

    NCA — International investigation disrupts the world's most harmful cyber crime group (20 Feb 2024)

  3. The US charged Russian national Dmitry Khoroshev as LockBit's administrator; Treasury sanctioned him and the State Department offered up to $10 million.

    US DOJ — U.S. charges Russian national with developing and operating LockBit ransomware (7 May 2024)

  4. LockBit announced version 4.0, which became available to affiliates in February 2025.

    Arete — LockBit 5.0: The RaaS That Refuses to Go Away (20 Jan 2026)

  5. LockBit announced version 5.0 on the RAMP forum in early September 2025.

    Arete — LockBit 5.0: The RaaS That Refuses to Go Away (20 Jan 2026)

  6. A new LockBit leak site went live in early December 2025.

    Arete — LockBit 5.0: The RaaS That Refuses to Go Away (20 Jan 2026)

  7. Arete counted more than 100 alleged victims posted to the new leak site.

    Arete — LockBit 5.0: The RaaS That Refuses to Go Away (20 Jan 2026)

Who is exposed, and what holds

Who is exposed

  • Organisations with unpatched internet-facing VPNs, gateways and remote access services
  • Virtualised estates running VMware ESXi or Proxmox, which LockBit 5.0 builds target
  • Victims weighing payment, who face sanctions exposure because of the OFAC designation of Khoroshev

Recommended controls

  • Patch edge devices promptly and enforce phishing-resistant MFA on all remote access
  • Keep offline, immutable and regularly tested backups, including of hypervisor hosts
  • Segment management networks and restrict administrative access to ESXi and backup servers

Sources