LockBit 2.0 has the ability to move laterally via SMB.34
tool
LockBit 2.0 S1199
- Type
- malware
- Platform
- Windows
- Created
- 24 January 2025
- Last modified
- 21 October 2025
LockBit 2.0 is an affiliate-based Ransomware-as-a-Service (RaaS) that has been in use since at least June 2021 as the successor to LockBit Ransomware. LockBit 2.0 has versions capable of infecting Windows and VMware ESXi virtual machines, and has been observed targeting multiple industry verticals globally.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1199
LockBit 2.0 can use wmic.exe to delete volume shadow copies.5
LockBit 2.0 can be executed via scheduled task.6
LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration.78
LockBit 2.0 can use the PowerShell module InvokeGPUpdate to modify Group Policy.910
LockBit 2.0 can use the Windows command shell for multiple post-compromise actions on objective.111213
Standing S1199
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
89th percentile · 89% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
80th percentile · 80% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
76th percentile · 76% of 825 ATT&CK software entries have this many detection rules per technique or fewer.
Detection coverage S1199
1347 distinct rules cover the 26 techniques recorded for this tool. The 1470 technique-to-rule mappings resolve to 1347 distinct rules, because one rule can cover several techniques. 895 Sigma · 452 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org