Malware · critical

How to fixLOCKBIT_3_RANSOMWARE

LockBit 3.0 (LockBit Black) Ransomware

What this error means

LockBit 3.0 (LockBit Black) Ransomware ranks as a critical-severity malware/security issue in our database. LockBit 3.0 (also known as LockBit Black) is a highly aggressive ransomware-as-a-service (RaaS) variant. It employs advanced anti-analysis techniques, disables security tools, and encrypts files using a multi-threaded engine while stealing sensitive data for extortion. The usual suspects are exploiting vulnerabilities in VPNs and edge firewalls, phishing campaigns containing malicious script attachments and compromised administrative credentials. Use the steps below to track down and fix the cause.

Before you begin

Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.

Work through these checks

0 of 4 complete
01Patch all public-facing edge equipment and VPNs immediately

Patch all public-facing edge equipment and VPNs immediately.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
02Implement strong application whitelisting and block execution from Temp directories

Implement strong application whitelisting and block execution from Temp directories.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
03Deploy tamper-protected endpoint security

Deploy tamper-protected endpoint security.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
04Restore systems from offline backups

Restore systems from offline backups.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help

Possible causes

  • Exploiting vulnerabilities in VPNs and edge firewalls
  • Phishing campaigns containing malicious script attachments
  • Compromised administrative credentials