/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail the increasingly prevalent LockBit ransomware, which may one day reach parity with other feared ransomware packages like Maze or Ryuk

You've probably never heard of LockBit, but that's likely to change.  —  Ransomware has emerged as one of the top threats facing large organizations …

Ars Technica Dan Goodin

Context & Ripple Effects

In May 2020, Ars Technica flagged LockBit as an obscure strain that researchers believed could reach parity with the era's most feared families — Ryuk, which had already pulled in roughly $3.7M in Bitcoin from resource-rich targets, and Maze, which was winding down. The prediction aged well: by late 2023, experts identified LockBit as the ransomware-as-a-service crew behind the Industrial and Commercial Bank of China hack, with the UK's Royal Mail among its other victims.

The arc since has been a boom-and-crackdown cycle. Chainalysis tallied at least $350M in ransomware proceeds for 2020, up 311% year over year, as the Ryuk-led payment surge peaked — and LockBit climbed into that vacuum. By February 2024, global law enforcement dealt Russia-linked LockBit what analysts called a major blow, though history suggested the gang would regroup.

First-order effects

  • Large organizations gain a new name on their threat lists: a strain researchers explicitly warned was built to threaten exactly the big-resource victims Ryuk favored, now operating as a service others can rent.
  • LockBit's shift to ransomware-as-a-service means its operators profit from affiliate attacks they don't personally execute — widening who can deploy it against enterprises like ICBC and Royal Mail.

Second-order effects

  • The affiliate model feeds the payment economy Chainalysis measured — hundreds of millions flowing annually — which in turn funds more crews and draws law enforcement attention, culminating in the February 2024 action against LockBit.
  • LockBit's weakening alongside BlackCat pressures rival gangs to absorb displaced affiliates and victims, reshuffling market share in the criminal ecosystem rather than shrinking it.

Third-order effects

  • The pattern across Maze's exit, Ryuk's dominance, LockBit's rise, and its eventual takedown points to ransomware behaving like a durable market: brands fall, but the service model and affiliate pool persist and rebrand.
  • Sustained law-enforcement pressure against RaaS infrastructure suggests the long-term battleground shifts from individual strains to the hosting, negotiation, and payment rails all these gangs share.

The trend: Ransomware is consolidating around rented service platforms whose brands rise and fall under enforcement pressure while the underlying affiliate economy endures.

Discussion

  • @john_fokker John Fokker on x
    Lockbit; a bespoke ransomware with serious aspirations. Great to see @dangoodin001 covering our research. @McAfee_Labs https://arstechnica.com/...
  • @_intelligencex Intelligence X on x
    Part of the reason why you shouldn't pay ransom: No guarantee it actually works. Screenshot from an actual conversation between a victim and the LockBit operators: https://twitter.com/... https://twitter.com/...
  • @john_fokker John Fokker on x
    “It seems that LockBit has joined the underground scene with a clear determination to do business; the authors have put a down a deposit in excess of 10,5 BTC” A LockBit deep-dive and Incident response case by @Seifreed @ValthekOn @Northwave_Sec and Myself https://www.mcafee.com/…
  • @raj_samani Raj Samani on x
    Introducing #LockBit #ransomware - heavily targeted with an actual helpdesk “ineffective in solving the technical issues” but with a “big boss” https://www.mcafee.com/... #malware #cybercrime H/T @John_Fokker @Seifreed https://twitter.com/...
  • @dangoodin001 Dan Goodin on x
    ICYMI: How a new piece of ransomware steamrolled a company in a matter of hours. For a newcomer, LockBit has several advanced features that will likely mean we'll be hearing more about this ransomware as a service in the future. https://twitter.com/...