LockBit — Affiliate Rules
The immortal oldest Ransomware affiliate program LockBit is excited to welcome you.
We have been working since September 3, 2019 and we are not going to stop no matter how much the intelligence services around the world want us to stop.
We are based in the Netherlands, fully apolitical and we are only interested in money. We always have unlimited and automatic recruitment of affiliates, no interviews or castings, just sign up at the following link http://lockbitfbinpwhbyomxkiqtwhwiyetrbkb4hnqmshaonqxmsrqwg7yad.onion/ and start working within 5 minutes. No matter what country you live in, what language you speak, your age, your religion, anyone on the planet can work with us at any time of the year.
We are ready to work with initial access brokers: sale or for a percentage of ransom, but you must trust us completely. We provide a fully transparent work process — you can control the communication with the victim, in case the company is encrypted and has not paid, you will see the stolen information on the blog.
We also work with those who are not involved in encryption, but just want to sell the stolen information by posting it on the largest and most invulnerable Ransomware blog on the planet.
A brief overview of the features: successful decryption even if the encryption process is interrupted at any stage; a Tor-based administrator panel; communication with companies in the Tor network, chat with notifications and the ability to transfer files; ability to create private chats for secret chats with Recovery companies; StealBit data stealer, with the ability to search for private files in automatic mode; automatic uploading of data in the blog, personally by you without our involvement, without buying servers, without buying cloud storage; the ability to upload pictures in the blog; ability to generate builds with different settings, but with one encryption key for one corporate network; 2 different encryptor lockers for Windows in one panel, written by different developers, which makes it possible to encrypt the network twice, if there is enough time, it will be useful for paranoid people who doubt the reliability and realization of the cryptographic algorithm and believe in free decryption, however, now free decryption is not possible and this is proven by the last hack of our administrative Lite panel with auto-registration for all people in May 2025, not even one decryptor was affected; the ability to edit the kill list for processes and services; the fastest and most efficient cleanup of free space after encryption, with no possibility of recovery; impersonation for automatically escalating privileges on local computers; SafeMode work to bypass antivirus and provide stronger encryption; automatic distribution to the domain network at runtime without the need of scripts, by using GPO or psexec methods; removal of shadow copies; deleting logs and self-cleaning, to make forensic analysis more difficult; shutting down the computer after end of work, to make it impossible to extract RAM; printing demands on network printers in infinite quantities; working on all versions of Windows, with very flexible settings (exe, dll, ReflectiveDll, ps1); works on all versions of ESXi from 4.0 to 8.0, with very flexible settings; works on all versions of Proxmox, with very flexible settings; works on multiple versions of Linux (14 architectures for NAS encryption, RedHat, KVM and others); All this and much more awaits you in case you register at the link http://lockbitfbinpwhbyomxkiqtwhwiyetrbkb4hnqmshaonqxmsrqwg7yad.onion/ and start working. If you have not found one of your desired functions, please let us know, we will add it specially for you.
Affiliate Program Rules: It is forbidden not to stick to agreements you made in chat before payment. For example, promising to give a file tree and then not doing it. You should be sure to download valuable data with every company attacked due to an offensive attack. If you can't bypass firewall settings and you don't have the ability to download data, a special StealBit stealer will help you. It is not forbidden to work with competitors, but it is obligatory to inform about it and explain why and what you like from competitors, we will realize any your worthy wishes, progress and constant development is very important to us. Categories of targets to attack: Allowed to attack critical infrastructure such as nuclear power plants, thermal power plants, hydroelectric power plants, and other similar organizations. * Allowed to attack the oil and gas industry, such as pipelines, gas pipelines, oil production stations, refineries, and other similar organizations. * Allowed to attack any non-profit organizations. * Allowed to attack any educational institutions. * Allowed to attack any medical facilities. * Allowed to attack police stations and any other law enforcement agencies. * Allowed to attack military bases and military installations. * Allowed to attack space organizations. * Allowed to attack government organizations. * these permits remain in force until an agreement is negotiated between the FBI and LockBit to not attack certain categories of attack targets. If you are reading this and these rules have not changed, it means that the FBI has not yet approached us for this agreement, and they are fine with allowing attacks on the above categories of organizations.
We personally hate to allow the attacks on the mentioned categories of targets, but all responsibility for the damage done to these companies lies on the people who attack them and the FBI, who provoke us into this policy by their actions or inactions, LockBit only provides weapons for attacks like Lockheed Martin does, and who suffers from those weapons depends only on those who use them. Lockheed Martin sells it to whoever the FBI and the US government give approval to. LockBit can listen to the FBI and the US government too if they want to. It is forbidden to attack post-Soviet countries such as: Armenia, Belarus, Georgia, Kazakhstan, Kyrgyzstan, Latvia, Lithuania, Moldova, Russia, Tajikistan, Turkmenistan, Uzbekistan, Ukraine, Estonia. This is due to the fact that most of our developers and partners were born and raised in the Soviet Union, the former largest country in the world, but at the moment we are located in the Netherlands, what could be better than Amsterdam?
The rate of interest in the affiliate program is 20% of the ransom amount, if you think this is too much and because of this you work with another affiliate program or use your own personal software, then do not deny yourself the pleasure of working with us, just increase the ransom amount by 20% and be happy. You will receive payments from companies to your personal wallets in any convenient currency and only then you transfer a percentage to our affiliate program. However, for ransom amounts over 50 thousand dollars, you give the attacked company 2 wallets for payment — one yours, to which the company will transfer 80%, and the second ours for 20%, so we will reduce the risks for you and for us. You personally negotiate with the attacked companies and decide for yourself how much to charge for your invaluable pentest work, which must surely be generously paid. If you wish, you can delegate the negotiations to us. If you have any questions, doubts or issues, you don't like something, please report it to the TOX support. If you are very shy, you can do it anonymously by creating a one-time TOX. It is very important for us to know about all our advantages and disadvantages in order to constantly improve the service.
To summarize, the reasons why it is better to work with us: LockBit brand — the whole planet knows about us, we are trusted by encrypted companies, we have shown everyone that it is safe to cooperate with us, we are responsible for our words, we have never cheated anyone and have always fulfilled our agreements. Decryptors work, stolen data is deleted. Stability: we have been working for 6 years, and no negative news regarding ransomware has been able to scare and stop us, and so far we have not been caught by the FBI. If they couldn't catch us in 6 years, they probably never will, and we will keep working. Probably the best software and the most extensive list of operating systems and architectures you can attack. Invulnerable decryption keys, and successful decryption in case of encryption interruption at any stage. You negotiate and make all decisions yourself. Payments to your wallet: we can't cheat you and make exit scam, as many affiliate programs have done and will do. Besides, for 6 years we have earned hundreds of millions of dollars, it is so much that there is no sense to ruin our reputation because of some insignificant amount that you personally plan to earn. We store stolen company data on our blog for as long as possible so that companies are afraid of leaks and pay for stolen data in case there are backups and there is no need to pay for the decrypter. We have no limits on payments — you can encrypt RDP of individuals or companies with any level of revenue, any payment is welcomed by us — both 5000 thousand dollars and 50 million dollars, because we love our work and the process itself, and money is just a pleasant bonus. The best Anti-DDoS protection, stability of communication with companies is very important for receiving payouts. Resistance to hacking, everyone knows that we have been hacked many times and each time we recovered our work and became even stronger and more secure, it will always be like this. Possibility to create private chats for secret dialogue with Recovery companies: it can be very useful for keeping correspondence secret and preventing the disruption of negotiations. Bug bounty program: we understand that there is always a possibility of a zero-day vulnerability attack and we fight this threat with all possible ways. Report any bugs to us and receive a generous reward.