Threat Actor Profile
Low Cybercriminal
Confidence Score
100%
Tags
ransomware ransomware.live
First Seen

Unknown

Last Updated

Unknown

Active Status
Active
Created

April 29, 2026

Indicators of Compromise

Loading IOCs…

IOC KQL for Sentinel
STIX Data
{'added_date': None,
 'client': '2003264@sit.singaporetech.edu.sg',
 'description': '',
 'firstseen': '2020-10-21T00:00:00+00:00',
 'group': 'lockbit',
 'has_negotiations': False,
 'has_ransomnote': True,
 'lastseen': '2021-08-23T00:00:00+00:00',
 'locations': [{'available': False,
                'fqdn': 'lockbitkodidilol.onion',
                'slug': 'http://lockbitkodidilol.onion',
                'title': '',
                'type': 'DLS'}],
 'negotiation_count': 0,
 'ransomnotes_count': 5,
 'tiaras_metadata': {'has_negotiations': False,
                     'has_ransomnote': True,
                     'locations': [{'available': False,
                                    'fqdn': 'lockbitkodidilol.onion',
                                    'slug': 'http://lockbitkodidilol.onion',
                                    'title': '',
                                    'type': 'DLS'}],
                     'negotiation_count': 0,
                     'ransomnotes_count': 5,
                     'ransomware_live_group': 'lockbit',
                     'tools': {},
                     'url': 'https://www.ransomware.live/group/lockbit',
                     'victims': 5,
                     'vulnerabilities': [{'CVE': 'CVE-2021-44228 ("Log4Shell")',
                                          'CVSS': 10.0,
                                          'Product': 'Log4j',
                                          'Vendor': 'Apache',
                                          'severity': 'CRITICAL'},
                                         {'CVE': 'CVE-2023-4966 '
                                                 '("Citrixbleed")',
                                          'CVSS': 9.4,
                                          'Product': 'NetScaler ADC & Gateway',
                                          'Vendor': 'Citrix',
                                          'severity': 'CRITICAL'},
                                         {'CVE': 'CVE-2018-13379',
                                          'CVSS': 9.1,
                                          'Product': 'FortiOS',
                                          'Vendor': 'Fortinet',
                                          'severity': 'CRITICAL'},
                                         {'CVE': 'CVE-2023-0669',
                                          'CVSS': 7.2,
                                          'Product': 'GoAnywhere Managed File '
                                                     'Transfer',
                                          'Vendor': 'Fortra',
                                          'severity': 'HIGH'},
                                         {'CVE': 'CVE-2021-22986',
                                          'CVSS': 9.8,
                                          'Product': 'iControl REST',
                                          'Vendor': 'F5',
                                          'severity': 'CRITICAL'},
                                         {'CVE': 'CVE-2023–27350 & '
                                                 'CVE-2023–27351',
                                          'CVSS': None,
                                          'Product': 'PaperCut Application '
                                                     'Server',
                                          'Vendor': 'PaperCut',
                                          'severity': 'UNKNOWN'},
                                         {'CVE': 'CVE-2020-1472 ("ZeroLogon")',
                                          'CVSS': 5.5,
                                          'Product': 'NetLogon',
                                          'Vendor': 'Windows',
                                          'severity': 'MEDIUM'},
                                         {'CVE': 'CVE-2019-0708 ("BlueKeep")',
                                          'CVSS': 9.8,
                                          'Product': 'Remote Desktop Services',
                                          'Vendor': 'Windows',
                                          'severity': 'CRITICAL'}]},
 'tiaras_source': 'ransomware.live',
 'tools': {},
 'ttps': [],
 'url': 'https://www.ransomware.live/group/lockbit',
 'victims': 5,
 'vulnerabilities': [{'CVE': 'CVE-2021-44228 ("Log4Shell")',
                      'CVSS': 10.0,
                      'Product': 'Log4j',
                      'Vendor': 'Apache',
                      'severity': 'CRITICAL'},
                     {'CVE': 'CVE-2023-4966 ("Citrixbleed")',
                      'CVSS': 9.4,
                      'Product': 'NetScaler ADC & Gateway',
                      'Vendor': 'Citrix',
                      'severity': 'CRITICAL'},
                     {'CVE': 'CVE-2018-13379',
                      'CVSS': 9.1,
                      'Product': 'FortiOS',
                      'Vendor': 'Fortinet',
                      'severity': 'CRITICAL'},
                     {'CVE': 'CVE-2023-0669',
                      'CVSS': 7.2,
                      'Product': 'GoAnywhere Managed File Transfer',
                      'Vendor': 'Fortra',
                      'severity': 'HIGH'},
                     {'CVE': 'CVE-2021-22986',
                      'CVSS': 9.8,
                      'Product': 'iControl REST',
                      'Vendor': 'F5',
                      'severity': 'CRITICAL'},
                     {'CVE': 'CVE-2023–27350 & CVE-2023–27351',
                      'CVSS': None,
                      'Product': 'PaperCut Application Server',
                      'Vendor': 'PaperCut',
                      'severity': 'UNKNOWN'},
                     {'CVE': 'CVE-2020-1472 ("ZeroLogon")',
                      'CVSS': 5.5,
                      'Product': 'NetLogon',
                      'Vendor': 'Windows',
                      'severity': 'MEDIUM'},
                     {'CVE': 'CVE-2019-0708 ("BlueKeep")',
                      'CVSS': 9.8,
                      'Product': 'Remote Desktop Services',
                      'Vendor': 'Windows',
                      'severity': 'CRITICAL'}]}
Quick Actions