Ransomware family
LockBit Ransomware Decryption & Data Recovery
- Active
- Critical
- Some versions decryptable
LockBit is one of the largest ransomware-as-a-service operations in the world. Despite the 2024 law-enforcement takedown it returned as LockBit 5.0, with working Windows, Linux and VMware ESXi payloads, and it remains one of the most frequently seen families in China.
- First seen
- 2019-09
- File extensions
- .abcd .lockbit .lockbit3
- Ransom notes
- Restore-My-Files.txt
- Affected platforms
- Windows / Linux / VMware ESXi
Family profile
- File extensions
- .abcd
- .lockbit
- .lockbit3
- .[9位随机字符]
- .[16位随机字符]
- Ransom notes
- Restore-My-Files.txt
- [9位随机字符].README.txt
- ReadMeForDecrypt.txt
- !!!-Restore-My-Files-!!!.txt
- Contact patterns
- Tor negotiation portal (.onion, victim ID login)
- LockBit leak site (.onion)
- Tox ID
- Aliases / versions
- ABCD Ransomware、LockBit 2.0 / LockBit Red、LockBit 3.0 / LockBit Black、LockBit Green、LockBit 4.0、LockBit 5.0(内部代号 ChuongDong)、LockBit5(泄露站与情报平台常用写法)
- First seen
- 2019-09
- Status
- Active
- Threat level
- Critical
- Affected platforms
- Windows
- Linux
- VMware ESXi
- Tags
- Prevalent in China
- Leak-site regular
- Resurgent
- Ransomware-as-a-Service
- Double extortion
- Targets virtualization
- RDP brute force
- Exploits vulnerabilities
- Active
During Operation Cronos (February 2024) the UK NCA and the US FBI seized LockBit infrastructure and recovered decryption keys; by June 2024 the FBI said it held more than 7,000 keys and matches victims through its IC3 portal. The Japanese police, with Europol support, developed a decryption feasibility checker for LockBit 3.0 Black, published on No More Ransom.
The limits matter: keys map to specific affiliates and specific encryption sessions, so not every victim can be matched to a usable key. The published tool is a command-line checker, not a universal decryptor. LockBit 4.0 and 5.0 payloads seen from 2024 onward are not covered and have no public decryption method today.
Latest activity
ransomware.live shows LockBit 5.0's leak site has named 359 victims since its September 2025 restart and was still posting daily on 8-10 September 2026. The brand is operational again; treat cases as double extortion.
SourcesLockBit listed U.S. Bancorp with a two-week deadline but no samples; the bank said its systems were not breached and traced it to a contractor of a third-party vendor. Leak-site claims need independent verification.
SourcesAn H1 2026 Italy report put LockBit5 joint-first with Qilin at 21 claimed victims out of 148, with nearly half of its activity in a March 2026 surge; manufacturing took 39.9% of all victims.
Sources
Overview
LockBit first appeared in September 2019 as "ABCD ransomware", shipped LockBit 2.0 with the StealBit exfiltration tool in 2021, and released LockBit 3.0 (LockBit Black) in June 2022, topping global victim counts for several years. It is a textbook ransomware-as-a-service operation: a core team builds the payload and negotiation platform while affiliates run intrusions for a share of the proceeds.
In February 2024 the UK National Crime Agency, the FBI and partners ran Operation Cronos, seizing the leak site and 34 servers and recovering a large number of decryption keys. The brand was damaged but not eliminated: in September 2025 multiple vendors confirmed LockBit 5.0 (codenamed ChuongDong) in active use, with working Windows, Linux and ESXi builds.
China context: 360's October 2025 report put LockBit third domestically at around 8.96% of observed infections. Unlike the smaller local families that simply brute-force RDP, LockBit cases are organised hands-on intrusions — take an exposed asset or remote-management channel, move laterally to the domain controller and the virtualization platform, exfiltrate data, then encrypt. Manufacturing, logistics and construction are the most common victims in China.
How to identify it
Extensions: early builds used .abcd and .lockbit; LockBit 3.0 switched to a 9-character random extension that differs per deployment; LockBit 5.0 uses 16 random characters. A meaningless random suffix is itself an indicator — do not classify the case as "unknown family" because the extension returns no search results.
Ransom notes: Restore-My-Files.txt (2.0); a README.txt prefixed with the same 9 random characters as the extension (3.0); ReadMeForDecrypt.txt (5.0); and !!!-Restore-My-Files-!!! on Linux/ESXi.
Other signs: the desktop wallpaper is replaced and encrypted-file icons swapped; Windows event logs are cleared after encryption; on ESXi, virtual machines are force-powered-off before .vmdk, .vmx and .vmsn files are encrypted; and the note offers only a Tor portal with a victim ID rather than an email address, while threatening publication on the leak site.
Infection vectors
LockBit affiliates use a wide mix of initial-access techniques. Four dominate in Chinese incidents: internet-exposed remote access (weak or reused RDP passwords, leaked VPN accounts, bastion hosts without multi-factor authentication); edge-device and web-application vulnerabilities, where delayed patching is the root cause; network access purchased from initial-access brokers; and phishing that delivers frameworks such as Cobalt Strike for hands-on follow-up.
Post-compromise behaviour is consistent: dump credentials, move laterally over SMB with PsExec or WMI, take the domain controller and deploy via Group Policy, while locating backup servers and the virtualization management plane. Virtualization and backups are primary targets — destroying backups and then encrypting ESXi datastores can take a whole data centre down in one pass. Data is usually exfiltrated with StealBit or Rclone beforehand.
Encryption behavior
LockBit markets itself on speed: AES encrypts file contents while each file's symmetric key is protected with RSA or elliptic-curve cryptography, and key material is per-host.
Intermittent (partial) encryption is the behaviour that matters operationally — large files have only part of their blocks encrypted. An entire file server can therefore be processed in tens of minutes, and large database files and virtual disks retain substantial intact original blocks, leaving room for structure-level repair. Whether that is usable depends on the build's encryption stride and which structures were hit, so it must be measured.
Destructive actions: deletes volume shadow copies and empties the recycle bin; terminates database, mail and backup-agent services so locked files can be encrypted; disables the Windows recovery environment and some security products; clears event logs afterwards. Linux and ESXi builds accept command-line targets and power off virtual machines before encrypting datastores. LockBit 5.0 adds Russian-locale avoidance and reflective DLL loading.
Assess before you act
Recoverability assessment
Bottom line first: LockBit's cryptography has no usable general weakness, so decryption cannot rely on breaking the algorithm. The realistic paths, in priority order:
1. Law-enforcement key matching (LockBit 3.0 and earlier only) If encryption predates 2024 and the build is LockBit 3.0, run the Decryption Checker for LockBit 3.0 from No More Ransom and request key matching through the FBI IC3 channel. Hit rates are modest but the cost is near zero, making it a mandatory first step. It does not apply to 4.0 or 5.0.
2. Backups, snapshots and shadow copies LockBit deletes shadow copies and attacks backup infrastructure, yet real cases leave gaps: offline or off-site media, backup servers not joined to the domain, versioned cloud object storage with object lock, and array- or NAS-side snapshots the ransomware cannot see. Inventory surviving backups immediately after isolation, before a second wave encrypts them.
3. Structure-level repair of large files Because of intermittent encryption, SQL Server .mdf/.ldf, Oracle .dbf, MySQL .ibd and ESXi .vmdk files usually retain large intact regions. Depending on how encryption was applied, a virtual disk can sometimes be repaired and guest files extracted, table-level data pulled from database files, and gaps closed by replaying transaction logs. This is repair, not decryption, and coverage is measured per table and per virtual machine.
4. Unencrypted copies and fragment recovery Report exports, downstream databases, read-only replicas, endpoint caches and mail attachments often hold usable data. Where new files replaced originals, fragments may still be recoverable, so stop all writes to affected volumes as early as possible.
We do not pay ransoms, do not negotiate on a client's behalf, and never promise that every file can be decrypted or restored.
Our response plan
Hit by LockBit ransomware? What to do
Step 1: Containment and evidence preservation
Cut lateral movement before rushing to power things off: isolate affected hosts and the ESXi management network, block inbound RDP/VPN, and disable suspicious domain accounts and any compromised administrative accounts. Do not reinstall, do not reformat, and do not keep writing to affected volumes.
Preserve evidence in parallel: memory images from hosts still running, system and security event logs, ESXi host logs, RDP/VPN authentication records, the original ransom notes, and a set of encrypted samples together with matching unencrypted originals for repair comparison. Because LockBit clears event logs, logs on network devices, bastion hosts and backup systems are often the more reliable source.
Step 2: Family identification and encryption analysis
Random extensions make suffix-based identification unreliable, so the build (2.0 / 3.0 / 4.0 / 5.0, and whether it is the Linux/ESXi payload) is confirmed from the ransom-note filename, wallpaper, payload characteristics and the shape of the negotiation portal.
Encryption analysis follows: whether encryption is intermittent, the block size and stride, header and footer marker structures, and which critical structures were damaged. This determines what Step 3 can offer — the repair outlook for the same .mdf file is completely different under intermittent versus full encryption. If the build is 3.0 and encryption predates 2024, the No More Ransom checker and an FBI IC3 key-matching request are started in parallel.
Step 3: Recoverability assessment and recovery planning
Assets are ranked by business priority (domain controllers, core databases, ERP/MES, virtualization platform, file servers, endpoints) and each is assessed for viable paths and expected coverage:
- Assets with usable backups or snapshots: restore, but only after confirming the media is neither encrypted nor carrying attacker persistence.
- Large files without backups: sample-based repair feasibility, with per-table or per-VM coverage estimates.
- Ordinary files without backups: fragment recovery and side-channel copies.
- Cases where a law-enforcement key may match: tracked as a separate parallel path.
The deliverable states plainly what can be recovered, to what level, how long it will take, and what is definitively unrecoverable. Nothing beyond the stated coverage estimate is promised.
Step 4: Recovery execution
All work is done on read-only images or copies; original disks are left untouched. Execution follows the plan:
- Virtualization: repair .vmdk structures and mount/extract guest data, or rebuild the VM in a clean environment and load recovered data back.
- Databases: structural repair and table-level extraction for SQL Server .mdf, Oracle .dbf and MySQL tablespaces, with transaction logs, archive logs and business-side documents replayed to close the delta.
- File servers: business-critical directories first, delivered in batches by department.
- Endpoints: fragment recovery plus consolidation of side-channel copies.
Every delivery batch is verified: record counts reconciled against the business system, sampled key documents checked, VM bootability and application availability confirmed. The recovery environment stays isolated from production until it is confirmed free of residual payloads.
Step 5: Attribution, hardening and sign-off
Reconstruct the full attack chain: the initial entry point (which VPN, RDP or edge vulnerability), how credentials were obtained, the lateral path, dwell time, whether data was exfiltrated, and an inventory of backdoors and scheduled tasks. Because LockBit is a double-extortion family, determining whether data left the network is mandatory — it drives regulatory notification and external communication.
Hardening is expressed as verifiable items: no internet-exposed RDP, multi-factor authentication enforced on all remote access, a patch baseline for edge devices and web applications, backups rebuilt around offline/off-site copies plus immutable storage with object lock and regular restore drills, the virtualization management plane on its own segment with its own credentials, tiered privileged accounts with logon restrictions, and EDR coverage with a closed alert loop. The engagement closes with an incident report, a sign-off checklist, log-retention arrangements and monitoring recommendations.
Risk warning
What not to do
- Do not reinstall the OS, rebuild partitions or reformat affected volumes — key material, the file structures repair depends on, and recoverable fragments all disappear with them.
- Do not run assorted decryptors or recovery utilities against original disks; work on read-only images, because every write reduces the chance of success.
- Do not delete ransom notes, encrypted samples or suspicious binaries — they are required for family and build identification and for decryption feasibility checks.
- Do not restore network connectivity before surviving backups are confirmed intact; a second encryption wave taking out the last backup is a common LockBit outcome.
- Do not use the compromised domain administrator account to log into other servers while investigating — that completes the attacker's lateral movement for them.
- Do not contact the negotiation portal to pay or negotiate on your own; beyond the financial and compliance risk, payment does not guarantee a working decryptor.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related scenarios
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
Related industries
Manufacturing Ransomware Response and Recovery
Ransomware in manufacturing hits information systems and production cadence at the same time: with ERP down there are no orders, with MES down there is no schedule, and an encrypted drawing library takes the process documentation for an entire product line with it. This page covers the asset profile, recovery priorities and targeted defences.
Logistics and Supply Chain Ransomware Response
Logistics is acutely time-sensitive: when TMS, WMS, dispatch and sorting systems stop, goods pile up in warehouses and on routes immediately, and the effect propagates up and down the supply chain. This page covers the sector's threat profile, a recovery order built around goods movement, and hardening for EDI-interconnected environments.
Construction and Real Estate Ransomware Response
In construction and real estate the core assets are drawings, models and project documentation — typically scattered across project-site NAS units, shared drives and personal computers with no unified backup. This page covers the sector's threat profile, recovery of drawings and BIM models, and defences for dispersed, multi-project environments.
Similar families
- No public decryptor
BlackCat
BlackCat (ALPHV) was the first major Rust-based ransomware-as-a-service operation, active from November 2021. It seized accounts through help-desk social engineering, encrypted ESXi and Windows estates under double extortion, and shut down in a March 2024 exit scam after keeping the Change Healthcare ransom — its key infrastructure no longer exists.
- Some versions decryptable
Akira
Akira is a ransomware-as-a-service operation that emerged in March 2023, breaking in through VPNs without MFA and edge-device flaws, then encrypting Windows estates and VMware ESXi clusters under double extortion. CISA's November 2025 advisory update calls it an imminent threat to critical infrastructure.
- No public decryptor
DragonForce
DragonForce is one of the most active ransomware cartels today. Since 2025 it has offered white-label encryptors and infrastructure to affiliates, hits virtualisation estates hard, and became widely known through the chain of UK retail attacks. No public decryptor exists.
- No public decryptor
Qilin
Qilin (formerly Agenda) is a Rust-rewritten cross-platform RaaS operation focused on VMware ESXi and Linux estates. It has ranked as the world's most active ransomware group for several consecutive quarters since 2025, with confirmed victims among electronics manufacturers in Taiwan and Hong Kong.
Related questions
- First response
What should I do if I've been hit by ransomware?
Isolate first and keep the power on: unplug the network cable or turn off Wi-Fi, but do not reboot, format, delete the ransom note or contact the attackers. Then work in order: confirm it is ransomware and whether it is still spreading, preserve the note, encrypted samples and logs, identify the family, inventory backups and snapshots to assess recovery paths, and report the incident. Do not reconnect restored systems until the entry point is closed, credentials are rotated and backdoors are removed.
- Recovery
Can files encrypted by ransomware be recovered?
Often in part, sometimes almost entirely, but nobody can promise it before seeing samples. Recoverability comes down to four things: the family and version (is there a public decryptor, seized keys or a known flaw), how the files were encrypted (in full, or only partly), which backups, snapshots and other copies survived, and what has been written to the disks since. Where a modern family encrypted files correctly and completely, no copies survive and the remnants have been overwritten, the data may genuinely be gone. Stop all writes and identify the family first.
- Ransom & cost
Should we pay the ransom after a ransomware attack?
We advise against treating payment as the default, and we neither pay ransoms nor negotiate on anyone's behalf. Some organisations do pay, but payment guarantees neither a working decryptor nor deletion of stolen data, it often invites repeat extortion, and buying and moving cryptocurrency for a ransom carries legal and sanctions exposure in China and abroad. Identify the family and establish what backups, snapshots and database repair can recover before deciding anything.
- Recovery
Which ransomware decryption tools exist, and are downloaded ones safe to use?
Yes, but not many. Legitimate free decryptors come from the No More Ransom project, law enforcement agencies and the official channels of vendors such as Emsisoft, Avast, Kaspersky, Bitdefender and 360, and each usually works only for specific versions of a specific family. Programs circulating online as universal or dedicated decryptors are often malware or paid scams. Even with a genuine tool, confirm the family and version match first, and run it only on copies of your files.
- First response
Infected with the Silver Fox trojan - what now, and how do I remove it?
Stop the losses first and remove the malware second. If money has already gone out, call the police (110 in mainland China) and your bank immediately - that comes before any technical step. Unplug the PC from the network but do not shut it down or reboot it, and stop using it for banking, WeChat, QQ, DingTalk or payment approvals. From a separate clean device, change passwords and sign out every other session; tell finance to hold and phone-verify each pending payment, and warn contacts and groups that messages from the account may be fake. Once evidence is preserved, sweep with genuine vendor tools and rebuild any machine confirmed as compromised.
- Aftermath
How do we report a ransomware attack to the police, and what should we prepare?
In mainland China, call 110 or file in person with the local public security bureau (a police station or its cyber security unit); the Ministry of Public Security's online cybercrime portal takes tip-offs, not emergencies. Preserve evidence first: the original ransom note, encrypted samples, attacker contact details and wallet address, key logs and an incident timeline. Separately, assess whether the incident is "relatively major" or above under the CAC's incident reporting measures, which set deadlines of 1 to 4 hours depending on the operator - the authorities' requirements prevail.
- Aftermath
A ransomware gang is threatening to publish our data - what should we do?
Do not respond or pay yet. First establish with evidence whether data actually left and what it was: check outbound traffic, archive staging, transfer tools such as Rclone, MEGA or WinSCP, and cloud sign-in and export logs, and compare any samples the attackers released against your own data - some threats are bluffs or recycled old leaks. Paying does not buy deletion: the UK's National Crime Agency found data belonging to victims who had paid still on LockBit's systems. Close the exfiltration path, rotate credentials, and assess notification duties under the PIPL and related rules.
FAQ
LockBit Frequently asked questions
Can files encrypted by LockBit be decrypted?
It depends on the build. LockBit 3.0 and earlier, encrypted before 2024: there is a real chance — Operation Cronos recovered over 7,000 keys, No More Ransom hosts a feasibility checker, and the FBI IC3 portal handles key matching. Keys are tied to specific affiliates and sessions, so hit rates are modest.
LockBit 4.0 / 5.0: no public decryption method exists and no exploitable cryptographic weakness is known. In that case effort should move to the realistic paths — inventorying backups and snapshots, structure-level repair of large files, and locating unencrypted copies — rather than waiting for a decryptor.
The extension is random characters — how do I confirm it is LockBit?
The random suffix is itself the clue. LockBit 3.0 uses 9 random characters and 5.0 uses 16, so finding no search results for the extension is expected. Confirmation comes from the ransom-note filename (a README.txt sharing the extension prefix, ReadMeForDecrypt.txt, or Restore-My-Files.txt), a replaced desktop wallpaper, a note that offers only a Tor portal and victim ID rather than an email address, and cleared Windows event logs. Handing the note plus two or three encrypted samples to a response team is usually enough to pin the build within hours.
LockBit encrypted our ESXi virtual machines — is there hope for the vmdk files?
There is room to assess, but no blanket answer. LockBit encrypts large files intermittently, so .vmdk images typically retain substantial intact regions; depending on how encryption was applied, it may be possible to repair the virtual disk structure and extract guest databases, files and configuration. The decisive variables are the encryption stride, whether the partition table and filesystem metadata were hit, and whether the disk is thin- or thick-provisioned.
The correct approach is to take read-only images of the ESXi datastores, run repair feasibility tests on a few representative .vmdk files, and decide the overall plan from the measured coverage. Array-side snapshots and backup-software copies should be checked at the same time.
Should we pay the LockBit ransom?
We do not pay ransoms and do not negotiate for clients, and we advise organisations not to pay on their own. Beyond the compliance and legal exposure of sending funds to a sanctioned criminal ecosystem, there are practical issues: after the law-enforcement action LockBit was documented keeping data it had promised to delete, so payment guarantees neither a working decryptor nor suppression of stolen data, and buggy decryptors can cause further damage to large files and databases.
Time is better spent on forensics, backup inventory and repair feasibility. In most cases the combined coverage of backups, structure-level repair and side-channel copies is more controllable than betting on a decryptor.
LockBit was taken down by law enforcement — why did we still get hit?
Operation Cronos in February 2024 seized infrastructure and badly damaged the brand, but it did not end it. In September 2025 multiple vendors confirmed LockBit 5.0 in active use with Windows, Linux and ESXi payloads, and 360's October 2025 China report still placed LockBit third by infection volume.
In addition, the LockBit 3.0 builder leaked in 2022, and several independent crews have deployed modified versions whose encryption behaviour closely resembles LockBit without being an official affiliate. So for any "LockBit-looking" case the first step is still build and sample identification, not a conclusion drawn from headlines.
Sources
- CISA #StopRansomware: LockBit 3.0 (AA23-075A)
- NCA: The NCA announces the disruption of LockBit with Operation Cronos
- Trend Micro: New LockBit 5.0 Targets Windows, Linux, ESXi
- No More Ransom: Decryption Tools(含 Decryption Checker for LockBit 3.0)
- 360:2025 年 10 月勒索软件流行态势分析
External links are provided for reference only. The content is published by third parties and does not represent our position.
Updated