LockBit Ransomware: What It Targets and What's Recoverable
LockBit, also known as LockBit 3.0 or LockBit Black, is one of the largest ransomware operations tracked, with a documented history of attacks across thousands of organizations globally since being added to tracking in mid-2022. It maintains extensive, frequently-rotated infrastructure — dozens of historical onion domains alongside currently active leak sites.
Going after backups directly
LockBit's documented toolkit includes Mimikatz and other credential-theft utilities, Active Directory reconnaissance (AdFind, BloodHound), Cobalt Strike and Metasploit for offensive operations, and — specifically — Veeam credential extraction. That last detail matters: the group doesn't just encrypt production data, it specifically targets the credentials that protect backup infrastructure, aiming to compromise the backup as well as the original.
What this means for recovery
Because Veeam credentials are a documented target, a LockBit incident calls for checking backup repository integrity independently of production systems — don't assume backups are clean just because the ransom note only mentions encrypted production data. Repository storage and backup files themselves can often still be assessed and partially recovered even where credentials were compromised, provided the underlying files weren't also encrypted or deleted.
Dealing with something like this now?
Contact AS for an initial assessment of your recovery situation.