LOADING

Type to search

Global Crackdown on LockBit: US and UK Authorities Seize Ransomware Websites, Unveil Decryption Tools

News

Global Crackdown on LockBit: US and UK Authorities Seize Ransomware Websites, Unveil Decryption Tools

Share
LockBit Ransomware Empire Crumbles: Servers Seized, Leaders Hunted

On February 20, 2024, law enforcement agencies from the United States and the United Kingdom successfully carried out a major operation against the LockBit ransomware group, known for its extensive and harmful cyberattacks across the globe. This group, responsible for over 2,000 attacks worldwide and extracting more than $120 million in ransom payments, saw its darknet sites taken over by authorities. These sites, previously used to shame and pressure victims into paying ransoms, now offer free recovery tools and display information about the arrests and charges against LockBit affiliates.

The operation, named “Operation Cronos,” resulted in the seizure of about thirty-four servers and the arrest of two individuals believed to be part of LockBit. Additionally, two indictments were unsealed, a LockBit decryption tool was made publicly available, and over 200 cryptocurrency accounts associated with the group’s financial operations were frozen.

LockBit, active since September 2019, has targeted a wide range of victims in the U.S. and internationally, generating vast sums through ransom demands. Operating on a ransomware-as-a-service model, the group provided the malware and infrastructure, while affiliates focused on identifying targets. Affiliates earned a significant share of the ransoms paid.

Europol disclosed that a thorough investigation led to the compromise of LockBit’s main platform and other critical assets, including servers in several countries. Two suspected LockBit members were apprehended in Poland and Ukraine, though details about these individuals remain limited.

The U.S. Department of Justice announced charges against two Russian nationals, Artur Sungatov and Ivan Gennadievich Kondratyev, for their involvement in LockBit attacks. These indictments add to previous charges against other affiliates, highlighting the international effort to dismantle the LockBit network.

The operation’s success provides valuable insights into the operations of ransomware groups and their affiliates, potentially impacting other ransomware operations. The infiltration of LockBit’s infrastructure, particularly through exploiting a vulnerability in PHP, has sparked discussion and ridicule within cybercriminal communities, especially concerning the group’s failure to detect the flaw through its bug bounty program.

In a move seen as mocking the group, federal investigators have also utilized LockBit’s victim shaming site to tease the reveal of “LockBitSupp,” a key figure within the group, adding a layer of psychological warfare to the operation.

The collaborative effort included contributions from law enforcement agencies across several countries, emphasizing the global commitment to combating cybercrime. Victims of LockBit attacks are encouraged to reach out to the FBI for assistance in decrypting affected systems, with additional support from a recovery tool developed by the Japanese Police and Europol.

This operation marks a significant blow to LockBit and demonstrates the effectiveness of international cooperation in the fight against cyber threats.

 

Author

  • Maya Pillai holds a degree in Computer Applications and has been writing on technology for over two decades. For the past two years, she has focused exclusively on cybersecurity, helping readers navigate everything from ransomware threats to endpoint protection. Through her blog The Review Hive, Maya distils complex cyber topics into clear, practical insights tailored for individuals and small businesses alike. Maya mentors aspiring writers on her second platform, mayapillaiwrites.com, blending technical expertise with storytelling finesse.

    View all posts
Tags:
Maya Pillai

Maya Pillai holds a degree in Computer Applications and has been writing on technology for over two decades. For the past two years, she has focused exclusively on cybersecurity, helping readers navigate everything from ransomware threats to endpoint protection. Through her blog The Review Hive, Maya distils complex cyber topics into clear, practical insights tailored for individuals and small businesses alike. Maya mentors aspiring writers on her second platform, mayapillaiwrites.com, blending technical expertise with storytelling finesse.

  • 1

4 Comments

  1. binance тркелу April 17, 2024

    Your article helped me a lot, is there any more related content? Thanks!

    Reply
  2. Thng dang k'y binance December 13, 2024

    Thanks for sharing. I read many of your blog posts, cool, your blog is very good. https://www.binance.com/ar-BH/register?ref=V2H9AFPY

    Reply
  3. binance referal code January 12, 2025

    Thanks for sharing. I read many of your blog posts, cool, your blog is very good.

    Reply
  4. blile May 6, 2025

    Happy to join conversations, share experiences, and gain fresh perspectives as I go.
    I’m interested in hearing diverse viewpoints and adding to the conversation when possible. Happy to hear different experiences and meeting like-minded people.
    That’s my site:https://automisto24.com.ua/

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *