s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.lockbit

📛 Threat Title

Malware family: LockBit

Category: LockBit First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.lockbit`. Printable name: LockBit.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain osx.lockbit VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.lockbit

IOC database

Type
domain
Value
osx.lockbit
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-osx.lockbit

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.lockbit

References (1)

Remediations (10)

  • web:arxiv.org

    Abstract LockBit has evolved from an obscure Ransomware-as-a-Service newcomer in 2019 to the most prolific ransomware franchise of 2024. Leveraging a recently leaked MySQL dump of the gang's management panel, this study offers an end-to-end reconstruction of LockBit's technical, behavioral, and financial apparatus. We recall the family's version timeline and map its tactics, techniques ...

  • web:attack.mitre.org

    LockBit 3.0 is an evolution of the LockBit Ransomware-as-a-Service (RaaS) offering with similarities to BlackMatter and BlackCat ransomware. LockBit 3.0 has been in use since at least June 2022 and features enhanced defense evasion and exfiltration tactics, robust encryption methods for Windows and VMware ESXi systems, and a more refined RaaS ...

  • web:cybersecsentinel.com

    Threat Group - LockBit operators Threat Type - Ransomware as a Service Exploited Vulnerabilities - Exposed remote access services, unpatched internet facing infrastructure, valid credential reuse, weak virtualisation hardening Malware Used - LockBit 5.0 Windows Linux and ESXi variants Threat Score - 7.5 🔴 High - Cross platform impact with ESXi targeting, rapid encryption, and

  • web:malwaretips.com

    LockBit 5.0 is the latest version of the LockBit ransomware family , one of the most active and dangerous ransomware groups in the world. It encrypts files on Windows, Linux, and VMware ESXi systems, appends a random 16-character extension to each file (e.g., file.docx.random), and drops a ransom note named ReadMeForDecrypt.txt.

  • web:www.cisa.gov

    LockBit ransomware operation functions as a Ransomware-as-a-Service (RaaS) model where affiliates are recruited to conduct ransomware attacks using LockBit ransomware tools and infrastructure.

  • web:www.sentinelone.com

    LockBit 3.0 raises the stakes with faster encryption and bigger payouts. Let's dive into its infiltration methods and learn how to defend your data today.

  • web:www.techradar.com

    Security researchers from Trend Micro recently published an in-depth technical analysis of the latest iteration of the LockBit ransomware family , discovered in September 2025, as LockBit ...

  • web:www.trendmicro.com

    Trend™ Research analyzed source binaries from the latest activity from notorious LockBit ransomware with their 5.0 version that exhibits advanced obfuscation, anti-analysis techniques, and seamless cross-platform capabilities for Windows, Linux, and ESXi systems.

  • web:www.uvcyber.com

    Treating ransomware as a persistent platform threat rather than a single- family challenge remains the most effective defensive stance. Why It Matters LockBit 5.0 matters because it illustrates the resilience and adaptability of modern ransomware operations, even after high-profile law enforcement takedowns.

  • web:www.vicarius.io

    This blog breaks down LockBit's evolution, the full attack lifecycle, and how defenders from CISOs to IT administrators can operationalize mitigation using tools like Vicarius vRx. The Evolution of LockBit : From Commodity to Complex LockBit began as a typical RaaS operation in 2019, but by 2021, it had outpaced many peers.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.