Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1202
MITRE ATT&CK Malware

LockBit 3.0 (S1202)

LockBit Black
ShareXLinkedInRedditHN

[LockBit 3.0](https://attack.mitre.org/software/S1202) is an evolution of the LockBit Ransomware-as-a-Service (RaaS) offering with similarities to BlackMatter and [BlackCat](https://attack.mitre.org/software/S1068) ransomware. [LockBit 3.0](https://attack.mitre.org/software/S1202) has been in use since at least June 2022 and features enhanced defense evasion and exfiltration tactics, robust encryption methods for Windows and VMware ESXi systems, and a more refined RaaS structure over its predecessors such as [LockBit 2.0](https://attack.mitre.org/software/S1199).(Citation: Sentinel Labs LockBit 3.0 JUL 2022)(Citation: Joint Cybersecurity Advisory LockBit JUN 2023)(Citation: Joint Cybersecurity Advisory LockBit 3.0 MAR 2023)(Citation: INCIBE-CERT LockBit MAR 2024)

Platforms: Windows

▪Techniques implemented (34)

T1140Deobfuscate/Decode Files or InformationT1573.001Symmetric CryptographyT1548.002Bypass User Account ControlT1484.001Group Policy ModificationT1059.001PowerShellT1112Modify RegistryT1480.002Mutual ExclusionT1027.013Encrypted/Encoded FileT1027.002Software PackingT1680Local Storage DiscoveryT1543.003Windows ServiceT1569.002Service ExecutionT1071.001Web ProtocolsT1106Native APIT1480Execution GuardrailsT1685.005Clear Windows Event LogsT1070.004File DeletionT1218.003CMSTPT1685Disable or Modify ToolsT1083File and Directory DiscoveryT1082System Information DiscoveryT1135Network Share DiscoveryT1132.001Standard EncodingT1622Debugger EvasionT1489Service StopT1547.004Winlogon Helper DLLT1057Process DiscoveryT1614.001System Language DiscoveryT1120Peripheral Device DiscoveryT1486Data Encrypted for ImpactT1021.002SMB/Windows Admin SharesT1688Safe Mode BootT1078.003Local AccountsT1490Inhibit System Recovery
S1202on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.