LockBit 4.0: The world's most dangerous ransomware group is back
Reading time: 6 minutes

LockBit 4.0: The World's Most Dangerous Ransomware Group is Back
In February 2024, a coordinated international law enforcement operation named "Operation Cronos" dismantled the infrastructure of LockBit, the ransomware group responsible for over a billion dollars in extortion payments worldwide. Led by the UK's National Crime Agency (NCA) in partnership with Europol, the FBI, and agencies from ten other countries, this operation seized LockBit's data leak sites on the dark web, arrested key affiliates, and publicly revealed the identity of the group's administrator, Russian national Dmitry Yuryevich Khoroshev.
Yet, by early 2025, LockBit had made its return — under a new identity and more dangerous than ever, as LockBit 4.0.
What Made LockBit So Dangerous?
LockBit operated as a "ransomware-as-a-service" (RaaS) platform: its core developers leased malware infrastructure to external affiliates, who carried out the attacks and paid back a portion of the ransom proceeds. At its peak in 2023, LockBit was behind approximately 23% of all known ransomware attacks globally, targeting hospitals, government bodies, financial institutions, and critical infrastructure.
Among its victims were:
Royal Mail (UK) — disruption of international parcel deliveries for several weeks
Boeing — leak of over 43 GB of sensitive data
ICBC Financial Services — disruption of clearing operations in the US Treasury market
Fulton County (Georgia) — compromise of sensitive legal and election documents
What Has Changed with LockBit 4.0?
The new variant introduced several technical enhancements designed to evade modern detection systems:
Faster encryption algorithms using intermittent encryption — encrypting only portions of files to speed up operations while remaining effective
Enhanced anti-analysis features, capable of detecting sandboxes and virtual environments used by security researchers
New affiliate recruitment strategies targeting disgruntled insiders within companies
Improved data exfiltration tools prior to encryption, maximizing double extortion leverage
The Global Response
Following LockBit's resurgence, the CISA (Cybersecurity and Infrastructure Security Agency) issued an updated advisory urging organizations to immediately patch known vulnerabilities, implement network segmentation, and maintain offline backups. ENISA (European Union) also published a revised threat landscape report, classifying LockBit 4.0 as a Tier 1 critical threat.
What Can Organizations Do?
Apply patches immediately: LockBit frequently exploits known vulnerabilities in unpatched VPNs and RDP endpoints.
Enable multi-factor authentication (MFA) on all remote access points.
Conduct simulation exercises for ransomware attacks.
Engage a Managed Detection and Response (MDR) provider for 24/7 continuous monitoring.
Maintain immutable offline backups, regularly tested.
The return of LockBit is a stark reminder that disrupting a ransomware group does not make the threat disappear. As long as economic incentives persist, new variants will emerge. Proactive defense remains the only viable long-term strategy.
Don't wait for a security breach.
The average cost of a data breach is $4.88 million.
