
LockBit 3.0: Affiliate Full Kill Chain
A LockBit 3.0 affiliate gained entry through a ProxyShell-class exploit on an internet-facing Exchange server, dropped a webshell as SYSTEM, harvested domain-admin credentials from LSASS on the domain controller, spread laterally across every high-value server, exfiltrated the primary data share with rclone, deleted all shadow copies and backup catalogs, and deployed the encryptor as a Windows service. Trace the complete kill chain from initial foothold to ransomware impact across SIEM event logs, XDR process telemetry, and perimeter firewall records.
Launches in 5 days
Tuesday, July 28, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
What you'll investigate
9 objectives unlock when this operation goes live.
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Jul 28, 2026, you can jump straight in.
Get Started Free