LockBit 4.0 Ransomware
First seen Jul 3, 2026 · Updated Jul 3, 2026 · CVSS 9.8
Fourth-generation LockBit ransomware-as-a-service with enhanced encryption completing full-disk encryption in under four minutes. Actively targeting hospitals, municipal governments, and manufacturing.
Technical Analysis
Initial access via CVE-2023-3519 (Citrix NetScaler RCE) and CVE-2024-21762 (Fortinet SSL-VPN). Uses ChaCha20-Poly1305 encryption with RSA-2048 wrapped keys. Deploys via DLL sideloading through legitimate Windows binaries.
Affected Systems
Windows Server 2016-2025, VMware ESXi 7.x/8.x, Linux with exposed SSH
Indicators of Compromise
- sha256:a3f5b...e91d
- C2: 185.220.xx.xx:443
- RESTORE-FILES.txt
- HKLM\SOFTWARE\LockBit4
Remediation Steps
- 1
Patch Edge Devices
Patch Citrix NetScaler and FortiGate immediately
- 2
Disable ESXi SSH
Run vim-cmd hostsvc/disable_ssh on all ESXi hosts
- 3
Rotate Credentials
Reset KRBTGT twice with 12h interval
- 4
Deploy Canary Files
Place decoy files in high-value directories
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.