U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
Key Facts
- Legal Status: CHARGED in U.S. District Court for the District of New Jersey.
- Primary Target Sector: Healthcare, Education, Manufacturing, Government, Financial Services.
- Documented Financial Loss: $500.0 million.
- 8 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Exploitation of perimeter gateway vulnerabilities (such as Citrix Bleed CVE-2023-4966) and acquisition of compromised corporate VPN logins from Initial Access Brokers (IABs).
Operational & Financial Fallout
Over 2,500 organizations breached worldwide across 120 countries, including Boeing, the UK Royal Mail, hospitals, and emergency dispatch centers. Extorted more than $500 million in ransom payments before an international coalition of 10 law enforcement agencies seized the infrastructure under Operation Cronos.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Exploitation of perimeter gateway vulnerabilities (such as Citrix Bleed CVE-2023-4966) and acquisition of compromised corporate VPN logins from Initial Access Brokers (IABs).
Adversary Kill Chain Flow
5 Documented PhasesAffiliates leveraged unpatched edge vulnerabilities like Citrix Bleed (CVE-2023-4966) to bypass multifactor authentication, or purchased valid network access tokens directly from dark web access brokers.
Operatives deployed vulnerable, legitimately signed third-party kernel drivers (Bring Your Own Vulnerable Driver attack) to disable antivirus software and endpoint detection and response (EDR) agents.
Before encrypting hosts, affiliates launched custom StealBit exfiltration executables, parsing local drives for office documents and intellectual property and parallel-uploading gigabytes of data to offshore servers.
LockBit 3.0 executed with command-line passkeys, using multiple CPU threads to encrypt files with AES and ECC algorithms, appending random extension strings and deleting volume shadow copies.
Victims were directed to a private Tor negotiation portal with a countdown clock. In February 2024, the FBI, UK NCA, and Europol executed Operation Cronos, taking over the admin panel and releasing decryption tools.
Over 2,500 organizations breached worldwide across 120 countries, including Boeing, the UK Royal Mail, hospitals, and emergency dispatch centers. Extorted more than $500 million in ransom payments before an international coalition of 10 law enforcement agencies seized the infrastructure under Operation Cronos.
Procedural & Incident Timeline
Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request.
Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks.
Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp).
U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Dmitry Yuryevich Khoroshev | Russian Federation | fugitive | Pending | $10.0 million | Developer and primary administrative operator of LockBit ransomware. Indicted in D.N.J. in May 2024 with a $10 million State Department reward. |
| Mikhail Vasiliev | Canadian and Russian | pleaded | Pending | None | High-profile LockBit affiliate arrested in Ontario, Canada, with firearms and cryptocurrency recovery. |
| Ruslan Magomedovich Astamirov | Russian Federation | charged | Pending | None | Arrested in Arizona in June 2023 for carrying out LockBit attacks against victims in Florida, Japan, and France. |
| Artur Sungatov | Russian Federation | fugitive | Pending | None | LockBit affiliate indicted in D.N.J. in February 2024 for targeting manufacturing and insurance firms. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1486 | Data Encrypted for Impact Impact | "LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal." | Indictment ¶ 12, Page 6 | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts." | Indictment ¶ 18, Page 9 | reviewed |
| T1490 | Inhibit System Recovery Impact | "The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery." | Indictment ¶ 14, Page 7 | reviewed |
| T1190 | Exploit Public-Facing Application Initial Access | "Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances." | CISA Advisory AA23-325A | reviewed |
| T1047 | Windows Management Instrumentation Execution | "LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets." | CISA Advisory AA23-165A ¶ 12 | reviewed |
| T1562.001 | Disable or Modify Tools Defense Evasion | "LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption." | Indictment ¶ 21, Page 11 | reviewed |
| T1558.003 | Kerberoasting Credential Access | "LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking." | CISA Advisory AA23-165A Appendix | reviewed |
| T1573 | Encrypted Channel Command and Control | "C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443." | Indictment ¶ 15, Page 8 | reviewed |
View 1 Proposed / Unverified Mapping Candidates
"Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals."
OFAC Sanctions Designations
State Department offers reward of up to $10,000,000 for information leading to the identification or location of Dmitry Khoroshev (aka LockBitSupp).
Treasury Release ↗Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia.
Treasury Release ↗Designated LockBit ransomware affiliate extradited from Canada.
Treasury Release ↗