ABCD ransomware
From extortion.wiki, the actor-lineage evidence directory
This evidence entity has no standalone negotiation-actor collection in the current Ransomchats snapshot. It exists to document a sourced relationship without rewriting or inventing a threat-actor URL.
Actor lineage
Global lineage directoryOverview
The joint LockBit advisory identifies ABCD ransomware as the predecessor to LockBit. This is software lineage and does not independently prove operator identity.
Documentary media

Known aliases
No source-supported alias is currently recorded. Malware names and actor-group names are not assumed to be equivalent.
Historical timeline
-
ABCD ransomware first observed
ABCD ransomware activity observed
The joint advisory dates first observed ABCD ransomware activity to September 2019 and identifies it as LockBit's predecessor.
Evidence status: officially confirmed ConfirmedRelated: LockBit
Lineage and relationships
| Related actor or family | Relationship | Period | Confidence | Evidence summary | Sources |
|---|---|---|---|---|---|
| LockBitoperation | Successorconfirmed · directed | From September 2019 | Confirmed | The joint LockBit advisory explicitly calls ABCD ransomware the predecessor to LockBit. This describes ransomware lineage and does not by itself prove uninterrupted operator identity.
| CISA, FBI, MS-ISAC, and international partners |
Predecessors
None established.
Successors
Splits and mergers
None established.
Suspected affiliate relationships
None established.
MITRE ATT&CK integration
No explicit MITRE ATT&CK group mapping is published for this source label. Software entries and fuzzy name matches are not promoted to group mappings.
External intelligence references
- Understanding Ransomware Threat Actors: LockBitCISA, FBI, MS-ISAC, and international partners · government advisory · primary authoritative
Confidence and evidence notes
Confidence applies to each individual alias, event, or relationship—not to the actor page as a whole. “Confirmed” requires explicit authoritative attribution or multiple strong independent sources. Moderate, low, disputed, and unknown entries retain the source's uncertainty. A malware-family name is not automatically an actor identity, and shared code or affiliates do not prove shared leadership.