Research page reference
ABCD ransomware lineage ABCD ransomware

Actor lineage

Global lineage directory

Overview

The joint LockBit advisory identifies ABCD ransomware as the predecessor to LockBit. This is software lineage and does not independently prove operator identity.

Documentary media

Known aliases

No source-supported alias is currently recorded. Malware names and actor-group names are not assumed to be equivalent.

Historical timeline

Lineage and relationships

Relationships shown from this actor's perspective
Related actor or familyRelationshipPeriodConfidenceEvidence summarySources
LockBitoperation Successorconfirmed · directed From September 2019 Confirmed

The joint LockBit advisory explicitly calls ABCD ransomware the predecessor to LockBit. This describes ransomware lineage and does not by itself prove uninterrupted operator identity.

  • CISA's LockBit evolution table records ABCD activity in September 2019 and identifies it as the predecessor to LockBit.
CISA, FBI, MS-ISAC, and international partners

Predecessors

None established.

Successors

Splits and mergers

None established.

Suspected affiliate relationships

None established.

MITRE ATT&CK integration

No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.

External intelligence references

  1. Understanding Ransomware Threat Actors: LockBitCISA, FBI, MS-ISAC, and international partners · government advisory · primary authoritative

Confidence and evidence notes

Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.