◉ PSYCHOHISTORY

LockBit (Ransomware-as-a-Service)

mechanismOccult & Esoteric · Darknet & Cyber
One rent-a-ransomware gang was behind a quarter of all ransomware attacks on Earth.
Who they are

LockBit, a syndicate that rents out ransomware to other criminals.

What they do

In the engine's read, it's the most prolific ransomware operation and a model of criminal resilience.

How it works

It was responsible for about 25% of all ransomware attacks in 2023-2024, got targeted by Operation Cronos in February 2024, and then rebuilt itself as LockBit 5.0 by late 2025/early 2026 with rewritten cross-platform software aimed at VMware ESXi and Linux.

Why it matters

It shows both the scale one criminal network can reach and how it bounces back after being disrupted.

The engine's record — word for word
Ransomware-as-a-Service syndicate. Most prolific ransomware operator globally — responsible for 25% of all ransomware attacks 2023-2024 period. Targeted by Operation Cronos February 2024. Reconstituted as LockBit 5.0 by late 2025 / early 2026 — rewritten platform-agnostic payloads targeting VMware ESXi hypervisors and Linux systems.
Follow the trail
Walk this on the live map →
Part of the Psychohistory engine — 2,426 entities, 6,314 documented connections. Open data, built to be proven wrong.