[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/lockbit-2-ransomware/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/lockbit-2-ransomware/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/ "High Profile Threats")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# LockBit 2.0: How This RaaS Operates and How to Protect Against It

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 16 min read  
Related Products  
[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Next-Generation Firewall icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Next-Generation Firewall](https://unit42.paloaltonetworks.com/product-category/next-generation-firewall/ "Next-Generation Firewall")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Amer Elsad](https://unit42.paloaltonetworks.com/author/amer-elsad/)
  * [JR Gumarin](https://unit42.paloaltonetworks.com/author/jr-gumarin/)
  * [Abigail Barr](https://unit42.paloaltonetworks.com/author/abigail-barr/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 9, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/)
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Flighty Scorpius](https://unit42.paloaltonetworks.com/tag/flighty-scorpius/)
  * [LockBit 2.0](https://unit42.paloaltonetworks.com/tag/lockbit-2-0/)
  * [RaaS](https://unit42.paloaltonetworks.com/tag/raas/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/lockbit-2-ransomware/?pdf=download&lg=en&_wpnonce=fafa58d2d0 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/lockbit-2-ransomware/?pdf=print&lg=en&_wpnonce=fafa58d2d0 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=LockBit%202.0:%20How%20This%20RaaS%20Operates%20and%20How%20to%20Protect%20Against%20It&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Flockbit-2-ransomware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Flockbit-2-ransomware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flockbit-2-ransomware%2F&title=LockBit%202.0:%20How%20This%20RaaS%20Operates%20and%20How%20to%20Protect%20Against%20It "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flockbit-2-ransomware%2F&text=LockBit%202.0:%20How%20This%20RaaS%20Operates%20and%20How%20to%20Protect%20Against%20It "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Flockbit-2-ransomware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=LockBit%202.0:%20How%20This%20RaaS%20Operates%20and%20How%20to%20Protect%20Against%20It%20https%3A%2F%2Funit42.paloaltonetworks.com%2Flockbit-2-ransomware%2F "Share in Mastodon")

## Executive Summary

LockBit 2.0 is ransomware as a service (RaaS) that first emerged in June 2021 as an upgrade to its predecessor LockBit (aka ABCD Ransomware), which was first observed in September 2019.

Since its inception, the LockBit 2.0 RaaS attracted affiliates via recruitment campaigns in underground forums, and thus became particularly prolific during the third quarter of calendar year 2021. The LockBit 2.0 operators claimed to have the fastest encryption software of any active ransomware strain as of June 2021, claiming accordingly that this added to its effectiveness and ability to disrupt the ransomware landscape.

While several top-tier RaaS affiliate programs, such as Babuk, [DarkSide](https://unit42.paloaltonetworks.com/darkside-ransomware/) and [REvil](https://unit42.paloaltonetworks.com/revil-threat-actors/) (aka Sodinokibi) disappeared from the underground in 2021, LockBit 2.0 continued to operate and gradually became one of the most active ransomware operations. While Conti was recognized as being the most prolific ransomware deployed in 2021 per our [2022 Unit 42 Ransomware Threat Report](https://start.paloaltonetworks.com/unit-42-ransomware-threat-report.html), LockBit 2.0 is the most impactful and widely deployed ransomware variant we have observed in all ransomware breaches during the first quarter of 2022, considering both leak site data and data from cases handled by Unit 42 incident responders.

According to data analysis of ransomware groups' dark web leak sites, LockBit 2.0 was the most impactful RaaS for five consecutive months. As of May 25, LockBit 2.0 accounted for 46% of all ransomware-related breach events for 2022. And the LockBit 2.0 RaaS leak site has the most significant number of published victims, with over 850 in total.

Additionally, LockBit 2.0 has affected many companies globally, with top victims based in the U.S., Italy and Germany. Its most highly targeted industry verticals include professional services, construction, wholesale and retail, and manufacturing.

Palo Alto Networks customers receive protections against LockBit 2.0 attacks from Cortex XDR, as well as from the WildFire cloud-delivered security subscription for the Next-Generation Firewall. (Please see the [Conclusion](#conclusion) section for more detail.)

|------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Related Unit 42 Topics | [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/), [Ransomware Threat Report](https://unit42.paloaltonetworks.com/2022-ransomware-threat-report-highlights/) |

## LockBit 2.0 Overview

LockBit 2.0 is another example of RaaS that leverages double extortion techniques as part of the attack to pressure victims into paying the ransom.

In some cases, LockBit 2.0 operators have performed DDoS attacks on the victims' infrastructure as well as using a leak site. This practice is known as triple extortion, a tactic observed in groups like BlackCat, Avaddon and SunCrypt in the past.

Like other ransomware families such as [BlackByte](https://unit42.paloaltonetworks.com/blackbyte-ransomware/), LockBit 2.0 avoids systems that use Eastern European languages, including many written with Cyrillic alphabets.

Unlike other RaaS programs that don't require the affiliates to be super technical or savvy, LockBit 2.0 operators allegedly only work with experienced penetration testers, especially those experienced with tools like Metasploit and [Cobalt Strike](https://unit42.paloaltonetworks.com/tag/cobalt-strike/). Affiliates are tasked with gaining initial access to the victim network, allowing LockBit 2.0 to conduct the rest of the attack.

LockBit 2.0 has been observed changing infected computers' backgrounds to a ransomware note. The ransomware note was also used to recruit insiders from victim organizations. The notes claimed the threat actors would pay "millions of dollars" to insiders who provided access to corporate networks or facilitated a ransomware infection by opening a phishing email and/or launching a payload manually. The threat actors also expressed interest in other access methods such as RDP, VPN and corporate email credentials. In exchange, they offer a cut of the paid ransom.

### Victimology

LockBit 2.0 targets organizations opportunistically. The operators work with initial access brokers to save time and allow for a larger profit potential. While typically seeking victims of opportunity, LockBit 2.0 does appear to have victim limitations. The group announced that they would not target healthcare facilities, social services, educational institutions, charitable organizations and other organizations that "contribute to the survival of the human race". However, despite these claims, there have been instances of affiliates undermining these guidelines by still opting to attack industry verticals such as healthcare and education.

Organizations in Europe and the U.S. are hit more often by LockBit 2.0 than those in other countries, likely due to the high profitability and insurance payouts.

### Leak Site Data

During the first calendar year quarter of 2022, LockBit 2.0 persisted as the most impactful and the most deployed ransomware variant we observed in all ransomware breaches shared on leak sites.
![LockBit 2.0 46%, Conti 17%, BlackCat (ALPHV) 10%, Stormous 6%, Hive 6%, Vice Society 5%, Black Basta 3%, BlackByte 3%, Cuba 3%, Kelvin Security 2%](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-13.png) Figure 1. Ransomware leak site data from the first calendar year quarter of 2022.

According to leak site data analysis, LockBit 2.0 was the most impactful RaaS for five consecutive months. As of May 25, LockBit 2.0 accounted for 46% of all ransomware-related breach events for 2022 shared on leak sites.

Additionally, the LockBit 2.0 RaaS leak site has the most significant number of published victims, with over 850 in total. The site itself typically features information such as victim domains, a time tracker and measures of how much data was compromised.
![A screenshot of the LockBit 2.0 extortion site. The header reads "conditions for partners and contacts."](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-14.png) Figure 2. LockBit 2.0 leak site extortion site.

LockBit 2.0 [claims](https://twitter.com/vxunderground/status/1523323798266785792) that they have demanded ransom from at least 12,125 companies, as shown in the figure below.
![A screenshot showing LockBit 2.0's claim that they have demanded ransom from at least 12,125 companies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-15.png) Figure 3. Source: VX-underground.

According to leak site data for LockBit 2.0, since its inception in June 2021, the RaaS has affected many companies globally, with top victims based in the U.S., Italy and Germany.
![Top 10 countries impacted by LockBit 2.0: United States 49.6%, Italy 9.6%, Germany 7.9%, Canada 6.6%, France 6.1%, United Kingdom 5.9%, Spain 4.8%, Thailand 3.5%, Brazil 3.1%, Switzerland 2.9%](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/chart-7.png) Figure 4. LockBit 2.0 geographical impact chart.

LockBit 2.0 has also impacted various victims across multiple industry verticals. Its most highly targeted industry verticals include professional services, construction, wholesale and retail and manufacturing.
![Top Leaked Industry Verticals - Professional and Legal 45.6%, Construction 12.8%, Federal Government 7.5%, Real Estate 7.3%, Wholesale and Retail 11.3%, High Tech 5.3%, Manufacturing 10.2%](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/chart-8.png) Figure 5. LockBit 2.0 impacted industry vertical chart.

When looking at leak site data across all ransomware families, we've observed LockBit 2.0 targeting the highest number of organizations in the following regions: JAPAC, EMEA, and LATAM.

### Unit 42 Incident Response Data on LockBit 2.0

Cases handled by Unit 42 security consultants involving LockBit 2.0 since its appearance in June 2021 demonstrate shorter dwell times and less flexibility in negotiation in the beginning of FY 2022 (measured October-September) in comparison to the end of FY 2021. The following data is broken into fiscal years and quarters based on when the threat actor breached the network, not when the activity was noticed by a client.

LockBit 2.0 has shown a decrease in dwell time in FY 2022. From the last two quarters of FY 2021 to the first two quarters of FY 2022, there has been an average 37-day difference.
![LockBit 2.0 Average Dwell Time - FY21 Q3 - approx 55 days, FY21 Q4 approx 73 days, FY22 Q1 approx 35 days, FY22 Q2 approx 18 days](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-16.png) Figure 6. LockBit 2.0 average dwell time by fiscal quarter.

The difference in initial and final ransom demands over the past fiscal year has been converted to percentages and then averaged. The graph below demonstrates that at the end of FY 2021, threat actors using LockBit 2.0 were much more open to negotiations of ransom amounts; during that time the ransom was dropped approximately 83% from the initial ask on average. In comparison, we see less flexibility in FY 2022 Q1 and Q3 -- threat actors only offered an average of about 30% as a price drop. FY 2022 Q2 is not included due to lack of sufficient information.
![LockBit 2.0 Average Difference in Initial vs Final Ransom - FY21 Q4 - approx 83%, FY22 Q1 - approx 30%, FY22 Q3 - approx 30%](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-17.png) Figure 7. LockBit 2.0 average difference in initial vs final ransom amount, shown as percentages.

## LockBit 2.0 Tactics, Techniques and Procedures

Technically speaking, we have observed LockBit 2.0 affiliates leveraging the following tactics, techniques and procedures:

|--------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **TA0001 Initial Access**                                                                                                                                                                                                                                                                                                                                                        ||
| T1078 Valid Accounts                                                     | Credentials that have either been reused across multiple platforms or have previously been exposed. Additionally, this includes VPN accounts -- not just domain and local accounts.                                                                                                                    |
| T1133 External Remote Services                                           | Affiliates have been seen brute forcing exposed RDP services and compromising accounts with weak passwords.                                                                                                                                                                                            |
| T1190 Exploit Public-Facing Applications                                 | Vulnerabilities such as ProxyShell (CVE-2021-34473) and improper SQL sanitization (CVE-2021-20028) have been observed being utilized as footholds into the environment.                                                                                                                                |
| **TA0002 Execution**                                                                                                                                                                                                                                                                                                                                                             ||
| T1053.005 Scheduled Task/Job                                             | Scheduled Task. LockBit 2.0 can be executed via scheduled tasks.                                                                                                                                                                                                                                       |
| T1059 Command and Scripting Interpreter                                  | LockBit 2.0 is typically executed via command line arguments via a hidden window.  Windows SysInternals PsExec has been utilized for both persistence and execution purposes. Its ability to execute processes on other systems spread the ransomware and assisted in reconnaissance activities. |
| **TA0003 Persistence**                                                                                                                                                                                                                                                                                                                                                           ||
| T1053.005 Scheduled Task/Job                                             | Scheduled Task. It was quite common to see scheduled tasks used to create persistence for the ransomware executable, PsExec, and occasionally some defense evasion batch scripts.                                                                                                                      |
| T1078 Valid Accounts                                                     | Compromised accounts may be used to maintain access to the network.                                                                                                                                                                                                                                    |
| T1136.001 Create Account                                                 | In rare cases, LockBit 2.0 has been observed to create accounts for persistence with simple names, such as "a."                                                                                                                                                                                        |
| T1505.003 Server Software Component                                      | With the upsurgence of ProxyShell, webshells have become more common entry points.                                                                                                                                                                                                                     |
| **TA0004 Privilege Escalation**                                                                                                                                                                                                                                                                                                                                                  ||
| T1068 Exploitation for Privilege Escalation                              | The ProxyShell elevation of privilege on the Exchange PowerShell Backend (CVE-2021-34523), Windows Background Intelligent Transfer Service (BITS) improperly handling symbolic links (CVE-2020-0787), and abusing the CMSTPLUA COM interface have all been seen as methods of privilege escalation.    |
| T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control | LockBit 2.0 has utilized a UAC bypass tool.                                                                                                                                                                                                                                                            |
| **TA0005 Defense Evasion**                                                                                                                                                                                                                                                                                                                                                       ||
| T1070 Indicator Removal on Host                                          | Indicators, such as logs in Windows Event Logs or malicious files, are typically removed using wevtutil, a batch script, or CCleaner.                                                                                                                                                                  |
| T1140 Deobfuscate/Decode Files or Information                            | Most PowerShell scripts involved in LockBit 2.0 cases are Base64 encoded.                                                                                                                                                                                                                              |
| T1484.001 Domain Policy Modification: Group Policy Modification          | LockBit 2.0 has been seen using the PowerShell module InvokeGPUpdate to update the group policy.                                                                                                                                                                                                       |
| T1562.001 Impair Defenses: Disable or Modify Tools                       | Windows Defender, other anti-malware solutions and monitoring tools are disabled utilizing a process explorer tool, a batch script or a specially crafted command line script.                                                                                                                         |
| T1564.003 Hide Artifacts: Hidden Window                                  | Affiliates use hidden windows to hide malicious activity from plain sight.                                                                                                                                                                                                                             |
| **TA0006 Credential Access**                                                                                                                                                                                                                                                                                                                                                     ||
| T1003 OS Credential Dumping                                              | As seen with other ransomware cases, Mimikatz is a key player in dumping credentials but LockBit 2.0 has been occasionally seen utilizing MiniDump as well.                                                                                                                                            |
| T1555 Credentials from Password Stores                                   | LockBit 2.0 has been seen utilizing numerous tools to dump passwords from password stores and Chrome using GrabChrome and GrabRFF.                                                                                                                                                                     |
| **TA0007 Discovery**                                                                                                                                                                                                                                                                                                                                                             ||
| T1046 Network Service Discovery                                          | Both Advanced Port Scanner and NetScan have been used to discover local network infrastructure devices and services running on remote hosts. Active Directory queries for remote systems have been performed by ADFind.                                                                                |
| T1057 Process Discovery                                                  | Process Explorer, Process Monitor and PCHunter have been utilized to discover any anti-malware or monitoring software and terminate it.                                                                                                                                                                |
| T1082 System Information Discovery                                       | LockBit 2.0 enumerates system information such as hostname, shares, and domain information.                                                                                                                                                                                                            |
| T1614 System Location Discovery                                          | Attempts to check the language settings.                                                                                                                                                                                                                                                               |
| **TA00008 Lateral Movement**                                                                                                                                                                                                                                                                                                                                                     ||
| T1021 Remote Services                                                    | Although Cobalt Strike has many capabilities beneficial to threat actors in ransomware attacks, it was mainly seen in LockBit 2.0 investigations acting as a command and control beacon, a method of lateral movement and a tool for downloading/executing files.                                      |
| T1021.002 Remote Services: SMB/Windows Admin Shares                      | LockBit 2.0 has been known to self-propagate via SMB.                                                                                                                                                                                                                                                  |
| **TA0010 Exfiltration**                                                                                                                                                                                                                                                                                                                                                          ||
| T1030 Data Transfer Size Limits                                          | In some cases, LockBit 2.0 will limit the data transfer sizes to fly under the radar of any monitoring services a client may have set up.                                                                                                                                                              |
| T1041 Exfiltration over C2 Channel                                       | MEGASync is the leading way for LockBit 2.0 affiliates to exfiltrate data from clients with it being occasionally replaced by RClone.                                                                                                                                                                  |
| **TA0011 Command and Control**                                                                                                                                                                                                                                                                                                                                                   ||
| T1219 Remote Access Software                                             | AnyDesk has been the most common legitimate desktop software used to establish an interactive command and control channel, with ConnectWise seen slightly less frequently.                                                                                                                             |
| **TA0040 Impact**                                                                                                                                                                                                                                                                                                                                                                ||
| T1486 Data Encrypted for Impact                                          | LockBit 2.0 is known for its extortion tactics, encrypting devices and demanding a ransom.                                                                                                                                                                                                             |
| T1489 Service Stop                                                       | During the defense evasion phase, anti-malware and monitoring software is often disabled. Firewall rules have occasionally been seen being disabled as well.                                                                                                                                           |

## LockBit 2.0 Technical Details

LockBit 2.0 was developed using the Assembly and Origin C programming languages and leverages advanced encryption standard (AES) and elliptic-curve cryptography (ECC) algorithms to encrypt victim data. It can affect both Windows and Linux OS, as the operator released a Linux version of LockBit 2.0 to target VMware ESXi hypervisor systems in October 2021, coded exclusively in the C programming language.

The LockBit group claimed that LockBit 2.0 is "the fastest encryption software all over the world" and provided a comparative table showing the encryption speed of various ransomware samples.
![Encryption speed comparative table for some ransomware - 02.08.2021 - The chart provided on the LockBit blog shows LockBit and LockBit 2.0 at the top of a list of encryption speed compared to other ransomware families. It also claims to self-spread.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-18.png) Figure 8. LockBit encryption comparative table | Source: LockBit blog.

LockBit 2.0 also contains a self-spreading feature, clears logs and can print the ransom note on network printers until the paper runs out.

A management panel that affiliates can use to manage victims and affiliate accounts, generate new ransomware builds and generate the decryptor if the demanded ransom is paid also exists.
![This screenshot of the ransomware management panel shows an example of a chat function that allows communication between threat actor and victim.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-19.png) Figure 9. LockBit 2.0 management panel. Source: ProDaft.

LockBit 2.0 operators also released an information-stealer dubbed StealBit, which was developed to support affiliates of the LockBit 2.0 RaaS when exfiltrating data from breached companies.

StealBit contains the following capabilities:

* Operates as a file grabber and dumps/uploads victim data to the LockBit victim-shaming site.
* No reliance on third-party cloud file-sharing services, where data can be easily removed if the victim submitted a complaint.
* The download speed is limited only by internet connection bandwidth, so it is possible to clone folders from corporate networks and upload them to the LockBit victim shaming blog quickly.

The operator of LockBit 2.0 has provided a comparative table speed showing the information stealer compared to other tools.
![Comparative table of the information download speed of the attacked company. - an information sheet provided by the operator of LockBit 2.0 ransomware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-20.png) Figure 10. LockBit 2.0 download speed, according to LockBit 2.0 operator.

## LockBit 3.0

There was a bug that existed in LockBit 2.0 that allowed researchers to revert the encryption process on an MSSQL database. After the bug's disclosure, LockBit forum members discussed how the bug will not exist in LockBit's next iteration. Moreover, on March 17, LockBit forum members mentioned the release of LockBit's next version in one or two weeks. On March 25, VX underground posted a [tweet](https://twitter.com/vxunderground/status/1528801206923141122) with details of this new version, dubbed LockBit Black.
![The screen reads: LockBit Black - All your important files are stolen and encrypted! You must find 7WYIIG83f.README.txt file and follow the instruction!](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/06/word-image-21.png) Figure 11. LockBit Black post-infection desktop wallpaper (Source: VX-underground).

## Courses of Action

Several adversarial techniques were observed in this activity and the following measures are suggested within Palo Alto Networks products and services to ensure mitigation of threats related to LockBit 2.0 ransomware, as well as other malware using similar techniques:

|---------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Product / Service**     | **Course of Action**                                                                                                                                                              |
| **Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion**                                                                                                                            ||
| The courses of action below mitigate the following techniques:  Exploit Public-Facing Application \[[T1190](https://attack.mitre.org/techniques/T1190)\], Command and Scripting Interpreter \[[T1059](https://attack.mitre.org/techniques/T1059)\], Local Account \[[T1136.001](https://attack.mitre.org/techniques/T1136/001)\], Web Shell \[[T1505.003](https://attack.mitre.org/techniques/T1505/003)\], Exploitation for Privilege Escalation \[[T1068](https://attack.mitre.org/techniques/T1068)\], Indicator Removal on Host \[[T1070](https://attack.mitre.org/techniques/T1070)\], Deobfuscate/Decode Files or Information \[[T1140](https://attack.mitre.org/techniques/T1140)\], Disable or Modify Tools \[[T1562.001](https://attack.mitre.org/techniques/T1562/001)\], Hidden Window \[[T1564.003](https://attack.mitre.org/techniques/T1564/003)\], Valid Accounts \[[T1078](https://attack.mitre.org/techniques/T1078)\], External Remote Services \[[T1133](https://attack.mitre.org/techniques/T1133)\], Scheduled Task \[[T1053.005](https://attack.mitre.org/techniques/T1053/005)\], Bypass User Account Control \[[T1548.002](https://attack.mitre.org/techniques/T1548/002)\], Group Policy Modification \[[T1484.001](https://attack.mitre.org/techniques/T1484/001)\] ||
| THREAT PREVENTION         | Ensure a secure Vulnerability Protection Profile is applied to all security rules allowing traffic                                                                                |
| THREAT PREVENTION         | Ensure a Vulnerability Protection Profile is set to block attacks against critical and high vulnerabilities, and set to default on medium, low, and informational vulnerabilities |
| THREAT PREVENTION         | Ensure DNS sinkholing is configured on all anti-spyware profiles in use                                                                                                           |
| THREAT PREVENTION         | Ensure an anti-spyware profile is configured to block on all spyware severity levels, categories, and threats                                                                     |
| THREAT PREVENTION         | Ensure a secure anti-spyware profile is applied to all security policies permitting traffic to the internet                                                                       |
| THREAT PREVENTION         | Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use                                                                                               |
| CORTEX XSOAR              | Deploy XSOAR Playbook Cortex XDR - Isolate Endpoint                                                                                                                               |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Block Account Generic                                                                                                                                     |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Access Investigation Playbook                                                                                                                             |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Impossible Traveler                                                                                                                                       |
| NEXT-GENERATION FIREWALLS | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                                                              |
| NEXT-GENERATION FIREWALLS | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                                                    |
| NEXT-GENERATION FIREWALLS | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources Exists                                                               |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID service account does not have interactive logon rights                                                                                                    |
| NEXT-GENERATION FIREWALLS | Define at least one 'Include Network'.                                                                                                                                            |
| NEXT-GENERATION FIREWALLS | Ensure that User-ID is only enabled for internal trusted interfaces                                                                                                               |
| NEXT-GENERATION FIREWALLS | Ensure that 'Include/Exclude Networks' is used if User-ID is enabled                                                                                                              |
| NEXT-GENERATION FIREWALLS | Ensure remote access capabilities for the User-ID service account are forbidden.                                                                                                  |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID Agent has minimal permissions if User-ID is enabled                                                                                                       |
| CORTEX XDR PREVENT        | Enable Anti-Malware Protection                                                                                                                                                    |
| CORTEX XDR PREVENT        | Enable Anti-Exploit Protection                                                                                                                                                    |
| CORTEX XDR PREVENT        | Configure Host Firewall Profile                                                                                                                                                   |
| CORTEX XDR PREVENT        | Configure Behavioral Threat Protection under the Malware Security Profile                                                                                                         |
| **Credential Access**                                                                                                                                                                                        ||
| The courses of action below mitigate the following techniques:  OS Credential Dumping \[[T1003](https://attack.mitre.org/techniques/T1003)\], Credentials from Password Stores \[[T1555](https://attack.mitre.org/techniques/T1555)\] ||
| CORTEX XDR PREVENT        | Enable Anti-Exploit Protection                                                                                                                                                    |
| CORTEX XDR PREVENT        | Enable Anti-Malware Protection                                                                                                                                                    |
| **Discovery**                                                                                                                                                                                                ||
| The below courses of action mitigate the following techniques:  Network Service Scanning \[[T1046](https://attack.mitre.org/techniques/T1046)\], Process Discovery \[[T1057](https://attack.mitre.org/techniques/T1057)\], System Location Discovery \[[T1614](https://attack.mitre.org/techniques/T1614)\], System Information Discovery \[[T1082](https://attack.mitre.org/techniques/T1082)\] ||
| CORTEX XDR PREVENT        | Configure Behavioral Threat Protection under the Malware Security Profile                                                                                                         |
| NEXT-GENERATION FIREWALLS | Ensure that all zones have Zone Protection Profiles with all Reconnaissance Protection settings enabled, tuned, and set to appropriate actions                                    |
| NEXT-GENERATION FIREWALLS | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                                                              |
| NEXT-GENERATION FIREWALLS | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources Exists                                                               |
| NEXT-GENERATION FIREWALLS | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                                                    |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Port Scan                                                                                                                                                 |
| **Lateral Movement**                                                                                                                                                                                         ||
| The courses of action below mitigate the following techniques:  Remote Services \[[T1021](https://attack.mitre.org/techniques/T1021)\], SMB/Windows Admin Shares \[[T1021.002](https://attack.mitre.org/techniques/T1021/002)\] ||
| NEXT-GENERATION FIREWALLS | Ensure remote access capabilities for the User-ID service account are forbidden.                                                                                                  |
| NEXT-GENERATION FIREWALLS | Ensure that User-ID is only enabled for internal trusted interfaces                                                                                                               |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID Agent has minimal permissions if User-ID is enabled                                                                                                       |
| NEXT-GENERATION FIREWALLS | Ensure that the User-ID service account does not have interactive logon rights                                                                                                    |
| NEXT-GENERATION FIREWALLS | Ensure that 'Include/Exclude Networks' is used if User-ID is enabled                                                                                                              |
| NEXT-GENERATION FIREWALLS | Ensure that security policies restrict User-ID Agent traffic from crossing into untrusted zones                                                                                   |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Block Account Generic                                                                                                                                     |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Access Investigation Playbook                                                                                                                             |
| **Command and Control**                                                                                                                                                                                      ||
| The courses of action below mitigate the following techniques:  Remote Access Software \[[T1219](https://attack.mitre.org/techniques/T1219)\]                                                          ||
| NEXT-GENERATION FIREWALLS | Ensure that the Certificate used for Decryption is Trusted                                                                                                                        |
| NEXT-GENERATION FIREWALLS | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                                                    |
| NEXT-GENERATION FIREWALLS | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources Exists                                                               |
| NEXT-GENERATION FIREWALLS | Ensure 'SSL Forward Proxy Policy' for traffic destined to the internet is configured                                                                                              |
| NEXT-GENERATION FIREWALLS | Ensure 'SSL Inbound Inspection' is required for all untrusted traffic destined for servers using SSL or TLS                                                                       |
| NEXT-GENERATION FIREWALLS | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                                                              |
| THREAT PREVENTION         | Ensure DNS sinkholing is configured on all anti-spyware profiles in use                                                                                                           |
| THREAT PREVENTION         | Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use                                                                                               |
| THREAT PREVENTION         | Ensure a secure anti-spyware profile is applied to all security policies permitting traffic to the Internet                                                                       |
| THREAT PREVENTION         | Ensure that antivirus profiles are set to block on all decoders except 'imap' and 'pop3'                                                                                          |
| THREAT PREVENTION         | Ensure an anti-spyware profile is configured to block on all spyware severity levels, categories, and threats                                                                     |
| THREAT PREVENTION         | Ensure a secure antivirus profile is applied to all relevant security policies                                                                                                    |
| URL FILTERING             | Ensure secure URL filtering is enabled for all security policies allowing traffic to the internet                                                                                 |
| URL FILTERING             | Ensure all HTTP Header Logging options are enabled                                                                                                                                |
| URL FILTERING             | Ensure that PAN-DB URL Filtering is used                                                                                                                                          |
| URL FILTERING             | Ensure that URL Filtering uses the action of 'block' or 'override' on the URL categories                                                                                          |
| URL FILTERING             | Ensure that access to every URL is logged                                                                                                                                         |
| CORTEX XSOAR              | Deploy XSOAR Playbook - PAN-OS Query Logs for Indicators                                                                                                                          |
| **Exfiltration**                                                                                                                                                                                             ||
| The courses of action below mitigate the following techniques:  Data Transfer Size Limits \[[T1030](https://attack.mitre.org/techniques/T1030)\], Exfiltration Over C2 Channel \[[T1041](https://attack.mitre.org/techniques/T1041)\] ||
| THREAT PREVENTION         | Ensure DNS sinkholing is configured on all anti-spyware profiles in use                                                                                                           |
| THREAT PREVENTION         | Ensure that antivirus profiles are set to block on all decoders except 'imap' and 'pop3'                                                                                          |
| THREAT PREVENTION         | Ensure an anti-spyware profile is configured to block on all spyware severity levels, categories, and threats                                                                     |
| THREAT PREVENTION         | Ensure passive DNS monitoring is set to enabled on all anti-spyware profiles in use                                                                                               |
| THREAT PREVENTION         | Ensure a secure anti-spyware profile is applied to all security policies permitting traffic to the Internet                                                                       |
| THREAT PREVENTION         | Ensure a secure antivirus profile is applied to all relevant security policies                                                                                                    |
| URL FILTERING             | Ensure that PAN-DB URL Filtering is used                                                                                                                                          |
| URL FILTERING             | Ensure that access to every URL is logged                                                                                                                                         |
| URL FILTERING             | Ensure that URL Filtering uses the action of 'block' or 'override' on the URL categories                                                                                          |
| URL FILTERING             | Ensure secure URL filtering is enabled for all security policies allowing traffic to the internet                                                                                 |
| URL FILTERING             | Ensure all HTTP Header Logging options are enabled                                                                                                                                |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Block URL                                                                                                                                                 |
| CORTEX XSOAR              | Deploy XSOAR Playbook - PAN-OS Query Logs for Indicators                                                                                                                          |
| CORTEX XSOAR              | Deploy XSOAR Playbook - Block IP                                                                                                                                                  |
| DNS SECURITY              | Enable DNS Security in Anti-Spyware profile                                                                                                                                       |
| NEXT-GENERATION FIREWALLS | Setup NetFlow Monitoring                                                                                                                                                          |
| NEXT-GENERATION FIREWALLS | Ensure application security policies exist when allowing traffic from an untrusted zone to a more trusted zone                                                                    |
| NEXT-GENERATION FIREWALLS | Ensure 'Service setting of ANY' in a security policy allowing traffic does not exist                                                                                              |
| NEXT-GENERATION FIREWALLS | Ensure 'Security Policy' denying any/all traffic to/from IP addresses on Trusted Threat Intelligence Sources Exists                                                               |
| **Impact**                                                                                                                                                                                                   ||
| The courses of action below mitigate the following techniques:  Data Encrypted for Impact \[[T1486](https://attack.mitre.org/techniques/T1486)\], Service Stop \[[T1489](https://attack.mitre.org/techniques/T1489)\] ||
| CORTEX XSOAR              | Deploy XSOAR Playbook - Ransomware Manual for incident response.                                                                                                                  |

*†These capabilities are part of the NGFW security subscriptions service
Note: This is not an all-inclusive list of the protections provided by Palo Alto Networks. This is a subset of our current Courses of Action initiative and will be updated as the project progresses.*

## Conclusion

LockBit 2.0 and its evolution over time is a perfect example to illustrate the persistence, increasing complexity and impact brought by the ransomware landscape as a whole. With claims of this RaaS offering the fastest encryption on the ransomware market, coupled with the fact that it has been delivered in high volume by experienced affiliates, this RaaS poses a significant threat. LockBit's continuation with operations and its next iteration coming up on the horizon means that organizations and their security teams need to stay vigilant in the ever-evolving threat landscape.

Palo Alto Networks detects and prevents LockBit 2.0 ransomware in the following ways:

* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire): All known samples are identified as malware.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr):
  * Identifies indicators associated with LockBit 2.0.
  * Anti-Ransomware Module to detect LockBit 2.0 encryption behaviors on Windows.
  * Local Analysis detection for LockBit 2.0 binaries on Windows.
* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall): DNS Signatures detect the known C2 domains, which are also categorized as malware in [Advanced](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)[URL Filtering](https://www.paloaltonetworks.com/products/threat-detection-and-prevention/web-security).

If you think you may have been compromised or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org).

## Appendix A

In August 2021, a Russian blogger published a 22-minute interview with an alleged representative of the group behind LockBit 2.0 called "LockBitSupp" on a YouTube channel called "[Russian-language open source intelligence (OSINT)](https://www.youtube.com/watch?v=ldgmx4ZCfFg)." The same Russian blogger previously published interviews with a representative of the group behind the REvil ransomware-as-a-service (RaaS), hackers and security experts.

**Some key takeaways from the claims made in the interview were:**

* The LockBit 2.0 threat actor claimed the group's RaaS was unlikely to be rebranded since the team allegedly was a business that was honest with their customers -- suggesting a supposed contrast between LockBit 2.0 and Avaddon, DarkSide and REvil affiliates.
* The LockBit 2.0 ransomware disregarded keyboard layout, but it allegedly would not run on a host where the system language was set to any of the languages spoken in the Commonwealth of Independent States region.
* The group did not devise attacks on companies of their choice; they simply worked with initial access to any corporate network they obtained elsewhere, since this was more profitable and saved time. The team selected targets for ransomware attacks based on the company's finances --- the bigger, the better. The location also did not matter. However, team members allegedly did not attack healthcare facilities, social services, educational institutions and charitable organizations or any other organization that "contributed to the survival of the human race." \[Note that Unit 42 case data does include indications that threat actors using LockBit 2.0 have targeted healthcare organizations at times.\]
* The threat actor claimed that the largest number of victims who paid ransom were company representatives who did not care about creating backup copies and did not protect their sensitive data. According to the threat actor's claims, companies that violated regulations about collecting and handling customer or user personal information were among those eager to pay. The threat actor claimed that there generally were only a few companies who refused to pay ransom on principle, while most of the victims evaluated profit and loss to decide whether or not to pay a ransom.
* LockBit 2.0 operators allegedly almost always offered discounts to their victims since the goal was to streamline attacks.
* The threat actor claimed that the COVID-19 pandemic facilitated ransomware attacks significantly, saying it was easy to compromise home computers of employees who work remotely and use them as a springboard to access other networked systems.
* Companies in Europe and the U.S. were hit with ransomware much more often than companies based in other countries allegedly because of high profit and insurance and not because of language barriers.
* Ransomware operators usually recruit negotiators, who coerce victims to pay ransom, since professional penetration testers allegedly lack the time for chatter.

## Additional Resources

[LockBit 3.0: Another Upgrade to the World's Most Active Ransomware](https://socradar.io/lockbit-3-another-upgrade-to-worlds-most-active-ransomware/)  
[Ransomware Groups to Watch: Emerging Threats](https://unit42.paloaltonetworks.com/emerging-ransomware-groups/)  
[Average Ransom Payment Up 71% This Year, Approaches $1 Million](https://www.paloaltonetworks.com/blog/2022/06/average-ransomware-payment-update/)  
[2022 Unit 42 Ransomware Threat Report Highlights](https://unit42.paloaltonetworks.com/2022-ransomware-threat-report-highlights/)  
Back to top

### Tags

* [Flighty Scorpius](https://unit42.paloaltonetworks.com/tag/flighty-scorpius/ "Flighty Scorpius")
* [LockBit 2.0](https://unit42.paloaltonetworks.com/tag/lockbit-2-0/ "LockBit 2.0")
* [RaaS](https://unit42.paloaltonetworks.com/tag/raas/ "RaaS")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022-26134) (Updated)](https://unit42.paloaltonetworks.com/cve-2022-26134-atlassian-code-execution-vulnerability/ "Threat Brief: Atlassian Confluence Remote Code Execution Vulnerability (CVE-2022-26134) (Updated)")

### Table of Contents

* 

### Related Articles

* [No Manners Here: The Ruthless Rise of The Gentlemen Ransomware](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/ "article - table of contents")
* [The Golden Scale: 'Tis the Season for Unwanted Gifts](https://unit42.paloaltonetworks.com/new-shinysp1d3r-ransomware/ "article - table of contents")
* [Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "article - table of contents")

## Related Ransomware Resources

![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Constellation image representing the constellation schema used by Palo Alto Networks Unit 42 to track nation-state and cybercrime threat actor groups](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/Generic-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 1, 2025 [#### Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/)

* [Academic Serpens](https://unit42.paloaltonetworks.com/tag/academic-serpens/ "Academic Serpens")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agonizing Serpens](https://unit42.paloaltonetworks.com/tag/agonizing-serpens/ "Agonizing Serpens")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) July 31, 2025 [#### Introducing Unit 42's Attribution Framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/tag/bookworm/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/ "Introducing Unit 42’s Attribution Framework")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![A pictorial representation of Akira ransomware, distributed by Howling Scorpius. A person's hand typing on a keyboard with a digital screen displaying the word "password" highlighted in blue, set against a backdrop of various cybersecurity interface graphics.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/09_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) December 2, 2024 [#### Threat Assessment: Howling Scorpius (Akira Ransomware)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/)

* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")

* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")

* [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/ "torrenting")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/ "Threat Assessment: Howling Scorpius (Akira Ransomware)")  
  ![Pictorial representation of a threat like BlackSuit ransomware. An illustration of a modern workspace with a laptop displaying cybersecurity icons, surrounded by stacks of coins and a credit card, all depicted in a neon, digital art style.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/04_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) November 20, 2024 [#### Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/)

* [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/ "BlackSuit ransomware")

* [Construction](https://unit42.paloaltonetworks.com/tag/construction/ "construction")

* [Education](https://unit42.paloaltonetworks.com/tag/education/ "Education")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/ "Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware")  
  ![A representation of a threat group like Jumpy Pisces. Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) October 30, 2024 [#### Jumpy Pisces Engages in Play Ransomware](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/ "Jumpy Pisces Engages in Play Ransomware")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Proactive Assessments](https://www.paloaltonetworks.com/unit42/assess)

* [Incident Response](https://www.paloaltonetworks.com/unit42/respond)

* [Transform Your Security Strategy](https://www.paloaltonetworks.com/unit42/transform)

* [Discover Threat Intelligence](https://www.paloaltonetworks.com/unit42/threat-intelligence-partners)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
