LockBit 2.0: What It Was and What Happened to LockBit

LockBit 2.0 was the version of the LockBit ransomware that appeared in June 2021. It added StealBit, a built-in tool for stealing […]

Madhurendra SachanBy Madhurendra Sachan
November 15, 2021
6 min read
Updated October 4, 2026
LockBit 2.0: What It Was and What Happened to LockBit

LockBit 2.0 was the version of the LockBit ransomware that appeared in June 2021. It added StealBit, a built-in tool for stealing data before encryption, and powered a ransomware-as-a-service operation that hit thousands of organisations. Law enforcement seized LockBit’s systems and its dark web leak site in February 2024, but affiliates still used the ransomware in 2025.

This post was first written in November 2021, when LockBit 2.0 attacks were rising in Chile, Italy, Taiwan and the UK. Here is the full picture: how LockBit worked, why its leak site mattered, what Operation Cronos did, and what defenders should take from it.

How LockBit evolved

LockBit started life as “ABCD” ransomware, named after the file extension it added to encrypted files. Later versions used the .lockbit extension. The joint advisory from CISA, the FBI and partner agencies, AA23-165A (2023), sets out the timeline:

DateEvent
September 2019First activity of ABCD ransomware, LockBit’s predecessor
January 2020LockBit-named ransomware appears on Russian-language crime forums
June 2021LockBit 2.0 (also called LockBit Red) arrives with the StealBit data theft tool
October 2021A Linux and VMware ESXi locker is added
March 2022LockBit 3.0 (LockBit Black) emerges
September 2022The LockBit 3.0 builder leaks, so non-affiliates can use it too
January 2023LockBit Green, built partly on Conti source code
February 2024Operation Cronos takes over LockBit’s infrastructure and leak site

The same advisory says LockBit was the most deployed ransomware variant in the world in 2022, and that the FBI counted about 1,700 LockBit attacks on US organisations since 2020, with roughly $91 million in ransoms paid.

How a LockBit 2.0 attack worked

LockBit ran as ransomware-as-a-service. A core group built and maintained the malware, the admin panel and the leak site. “Affiliates” rented that toolkit, broke into victims and kept most of the ransom. Because affiliates were many and unconnected, the way they broke in varied a lot. Common routes included:

  • Exposed remote desktop (RDP) and VPN logins protected only by passwords that had been guessed, reused or bought.
  • Unpatched internet-facing systems. AA23-165A lists exploited flaws including the Fortinet VPN bug CVE-2018-13379 and Log4Shell, CVE-2021-44228.
  • Phishing emails that delivered a first-stage loader or stole a login.
  • Access sold by initial access brokers on criminal forums.

Once inside, affiliates moved across the network, disabled security tools and backups, copied data out with StealBit or other tools, and only then encrypted systems. This is double extortion: pay to get a decryptor, and pay again to stop the stolen data appearing on the leak site.

Why the leak site mattered

LockBit’s leak site lived on the dark web, reachable through Tor. Each new victim got a post with a countdown timer and a sample of stolen files. The site served two purposes. It put public pressure on the victim, and it advertised the brand to new affiliates.

For defenders, leak sites and the forums around them are an early warning system. A company’s name, a supplier’s name, or a sale of “VPN access” to a firm in your sector often shows up there before anyone inside the victim has noticed the breach. That is why ransomware leak sites and access markets are a standard part of dark web monitoring.

Operation Cronos: the 2024 takedown

On February 20, 2024, the UK’s National Crime Agency announced that it had taken control of LockBit’s services in Operation Cronos, working with the FBI and partners from nine other countries. According to the NCA:

  • It seized LockBit’s main administration environment and the dark web leak site, then used the leak site to publish information about the gang itself.
  • StealBit infrastructure in three countries and 28 servers belonging to affiliates were taken down.
  • Two people were arrested in Poland and Ukraine, and more than 200 cryptocurrency accounts linked to the group were frozen.
  • Investigators recovered over 1,000 decryption keys to help victims.

One finding matters to anyone weighing a ransom. The NCA found data belonging to victims who had paid, which shows that paying does not guarantee the criminals delete what they stole.

Is LockBit still a threat?

Yes, at a reduced level. The brand was badly damaged, and the leaked 3.0 builder means “LockBit” infections are not always run by the original gang. LockBit was still the seventh most reported ransomware variant in the FBI’s 2025 Internet Crime Report, behind newer names such as Akira and Qilin. The techniques LockBit made popular, from affiliate programmes to double extortion, are now standard across the ransomware business.

What to do: practical defences

  1. Close the front doors. Put MFA on every VPN, RDP gateway, webmail and admin portal. Remove RDP from the open internet.
  2. Patch internet-facing systems first. Track CISA’s Known Exploited Vulnerabilities list and fix anything on it that you run.
  3. Keep backups attackers can’t reach. Use offline or immutable copies, and test a full restore.
  4. Watch for data leaving. Large outbound transfers to unfamiliar cloud storage are often the first sign of double extortion.
  5. Monitor the dark web for your name. Look for leaked credentials, access sales and leak site posts about you and your key suppliers.
  6. Report quickly. In India, the CERT-In Directions of April 28, 2022 require service providers, data centres, companies and government bodies to report cyber incidents to CERT-In within 6 hours of noticing them. In the US, report to the FBI through IC3.

Ransomware often starts with a stolen password, so the signs in compromised account signals and prevention are worth reading alongside this, as is our overview of what ransomware is.

FAQ

What is the difference between LockBit 2.0 and LockBit 3.0?

LockBit 2.0, from June 2021, added StealBit, a built-in tool for copying data out before encryption. LockBit 3.0, also called LockBit Black, appeared in March 2022 and shares similarities with BlackMatter and BlackCat ransomware. Its builder leaked in September 2022, so attacks using 3.0 are not always run by LockBit’s own affiliates.

Was LockBit shut down?

Its infrastructure was seized on February 20, 2024, in Operation Cronos, led by the UK’s National Crime Agency with the FBI. Arrests, indictments and frozen crypto accounts followed. The group tried to rebuild, and LockBit still appeared among the ten most reported ransomware variants in the FBI’s 2025 report, but at far lower volume than at its peak.

Should a LockBit victim pay the ransom?

Law enforcement agencies advise against it. When the NCA took over LockBit’s systems, it found data belonging to victims who had already paid, so payment did not guarantee deletion. Report the incident, isolate affected systems, and check the No More Ransom project and your authorities for available decryption keys before deciding anything.

Want to learn more about protecting your organization?

Talk to a TIKAJ security expert and discover how our platform can help secure your digital ecosystem.

Get in Touch