// THREAT ACTOR
LOCKBIT4_
DormantLOCKBIT4 is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem — file encryption combined with the threat of stolen-data publication on a public leak site — and continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of LOCKBIT4 — incident write-ups, attribution notes, and additional context — see the Threat Groups archive or run a site search.
Leak site mirrors
5 mirrors tracked, 0 currently reachable. These are criminal-infrastructure URLs — links are deliberately not provided.
-
lockbitapyx2kr5b7ma7qn6ziwqgbrij2czhcbojuxmgnwpkgv2yx2yd.onionLockBit 5.0 OUT! snapshot · 2025-12-12 22:10 -
lockbitapyum2wks2lbcnrovcgxj7ne3ua7hhcmshh3s3ajtpookohqd.onionLockBit Tech Works snapshot · 2025-06-03 06:14 -
lockbitapp24bvbi43n3qmtfcasf2veaeagjxatgbwtxnsh5w32mljad.onionLockBit 5.0 OUT! snapshot · 2025-12-13 00:12 -
lockbitapo3wkqddx2ka7t45hejurybzzjpos4cpeliudgv35kkizrid.onionLockBit 5.0 OUT! snapshot · 2026-07-09 12:54 -
lockbitapiahy43zttdhslabjvx4q6k24xx7r33qtcvwqehmnnqxy3yd.onionLockBit 5.0 OUT! snapshot · 2025-11-21 08:11