LockBit 3.0
MITREOther
Unknown
Unknown
[LockBit 3.0](https://attack.mitre.org/software/S1202) is an evolution of the LockBit Ransomware-as-a-Service (RaaS) offering with similarities to BlackMatter and [BlackCat](https://attack.mitre.org/software/S1068) ransomware. [LockBit 3.0](https://attack.mitre.org/software/S1202) has been in use since at least June 2022 and features enhanced defense evasion and exfiltration tactics, robust encryption methods for Windows and VMware ESXi systems, and a more refined RaaS structure over its predecessors such as [LockBit 2.0](https://attack.mitre.org/software/S1199).(Citation: Sentinel Labs LockBit 3.0 JUL 2022)(Citation: Joint Cybersecurity Advisory LockBit JUN 2023)(Citation: Joint Cybersecurity Advisory LockBit 3.0 MAR 2023)(Citation: INCIBE-CERT LockBit MAR 2024)
Tecniche Associate (34)
| ID | ATT&CK | Tattiche |
|---|---|---|
| T1021.002 | SMB/Windows Admin Shares | - |
| T1027.002 | Software Packing | - |
| T1027.013 | Encrypted/Encoded File | - |
| T1057 | Process Discovery | - |
| T1059.001 | PowerShell | - |
| T1070.001 | Clear Windows Event Logs | - |
| T1070.004 | File Deletion | - |
| T1071.001 | Web Protocols | - |
| T1078.003 | Local Accounts | - |
| T1082 | System Information Discovery | - |
| T1083 | File and Directory Discovery | - |
| T1106 | Native API | - |
| T1112 | Modify Registry | - |
| T1120 | Peripheral Device Discovery | - |
| T1132.001 | Standard Encoding | - |
Alias (105)
Metadata
| ID: | 325 |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |