criticalRansomware

LockBit 4.0 Ransomware

First seen Jul 3, 2026 · Updated Jul 3, 2026 · CVSS 9.8

RansomwareHealthcareRaaS

Fourth-generation LockBit ransomware-as-a-service with enhanced encryption completing full-disk encryption in under four minutes. Actively targeting hospitals, municipal governments, and manufacturing.

Technical Analysis

Initial access via CVE-2023-3519 (Citrix NetScaler RCE) and CVE-2024-21762 (Fortinet SSL-VPN). Uses ChaCha20-Poly1305 encryption with RSA-2048 wrapped keys. Deploys via DLL sideloading through legitimate Windows binaries.

Affected Systems

Windows Server 2016-2025, VMware ESXi 7.x/8.x, Linux with exposed SSH

Indicators of Compromise

  • sha256:a3f5b...e91d
  • C2: 185.220.xx.xx:443
  • RESTORE-FILES.txt
  • HKLM\SOFTWARE\LockBit4

Remediation Steps

  1. 1

    Patch Edge Devices

    Patch Citrix NetScaler and FortiGate immediately

  2. 2

    Disable ESXi SSH

    Run vim-cmd hostsvc/disable_ssh on all ESXi hosts

  3. 3

    Rotate Credentials

    Reset KRBTGT twice with 12h interval

  4. 4

    Deploy Canary Files

    Place decoy files in high-value directories

CVE / Advisory IDs

CVE-2023-3519CVE-2024-21762

Industries Most Exposed

HealthcareGovernmentManufacturing

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.