CASE DOSSIER charged

U.S. v. Khoroshev et al. (LockBit Ransomware Operation)

Docket: 2:24-cr-00330 Court: U.S. District Court for the District of New Jersey Opened: 2024-05-07 Sector: Healthcare, Education, Manufacturing, Government, Financial Services

Key Facts

Status
CHARGED
Legal disposition
Loss Amount
$500.0 million
Extorted more than $500 million in ransom payments and caused billions in remediation costs across 2,500 victims.
Techniques
8
Verified mappings
Defendants
4
Named in charges
  • Legal Status: CHARGED in U.S. District Court for the District of New Jersey.
  • Primary Target Sector: Healthcare, Education, Manufacturing, Government, Financial Services.
  • Documented Financial Loss: $500.0 million.
  • 8 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Exploitation of perimeter gateway vulnerabilities (such as Citrix Bleed CVE-2023-4966) and acquisition of compromised corporate VPN logins from Initial Access Brokers (IABs).

Operational & Financial Fallout

Over 2,500 organizations breached worldwide across 120 countries, including Boeing, the UK Royal Mail, hospitals, and emergency dispatch centers. Extorted more than $500 million in ransom payments before an international coalition of 10 law enforcement agencies seized the infrastructure under Operation Cronos.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Exploitation of perimeter gateway vulnerabilities (such as Citrix Bleed CVE-2023-4966) and acquisition of compromised corporate VPN logins from Initial Access Brokers (IABs).

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Access Perimeter Vulnerability Exploitation & Broker Credentials
MITRE ATT&CK T1190 →

Affiliates leveraged unpatched edge vulnerabilities like Citrix Bleed (CVE-2023-4966) to bypass multifactor authentication, or purchased valid network access tokens directly from dark web access brokers.

Artifacts & Tooling: CVE-2023-4966 Initial Access Broker logins
2
Defense Evasion BYOVD Endpoint Protection Neutralization
MITRE ATT&CK T1562.001 →

Operatives deployed vulnerable, legitimately signed third-party kernel drivers (Bring Your Own Vulnerable Driver attack) to disable antivirus software and endpoint detection and response (EDR) agents.

Artifacts & Tooling: Vulnerable signed kernel drivers EDR termination scripts
3
High-Speed Exfiltration StealBit Automated Data Theft
MITRE ATT&CK T1041 →

Before encrypting hosts, affiliates launched custom StealBit exfiltration executables, parsing local drives for office documents and intellectual property and parallel-uploading gigabytes of data to offshore servers.

Artifacts & Tooling: StealBit.exe Multi-connection FTP/HTTP uploads
4
Encryption Multi-Threaded LockBit 3.0 Black Detonation
MITRE ATT&CK T1486 →

LockBit 3.0 executed with command-line passkeys, using multiple CPU threads to encrypt files with AES and ECC algorithms, appending random extension strings and deleting volume shadow copies.

Artifacts & Tooling: LockBit 3.0 payload vssadmin delete shadows /all /quiet
5
Extortion & Infrastructure Seizure Automated Tor Panel Extortion & Operation Cronos Takedown
MITRE ATT&CK T1490 →

Victims were directed to a private Tor negotiation portal with a countdown clock. In February 2024, the FBI, UK NCA, and Europol executed Operation Cronos, taking over the admin panel and releasing decryption tools.

Artifacts & Tooling: Tor negotiation portal Operation Cronos law enforcement splash screen
Real-World Blast Radius & Operational Fallout

Over 2,500 organizations breached worldwide across 120 countries, including Boeing, the UK Royal Mail, hospitals, and emergency dispatch centers. Extorted more than $500 million in ransom payments before an international coalition of 10 law enforcement agencies seized the infrastructure under Operation Cronos.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enable Microsoft Vulnerable Driver Blocklist and Driver Signature Enforcement to thwart BYOVD attacks.
✓ Patch public-facing SSL-VPN and gateway appliances within 24 hours of KEV notification.
✓ Block shadow copy deletion commands (vssadmin, wmic shadowcopy) via endpoint behavioral rules.
✓ Maintain immutable, physically isolated offline backups of Active Directory and critical servers.

Procedural & Incident Timeline

2022-11-10 arrest

Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request.

2023-06-14 arrest

Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks.

2024-05-07 indictment

Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp).

2024-05-07 sanction

U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Dmitry Yuryevich Khoroshev Russian Federation fugitive Pending $10.0 million Developer and primary administrative operator of LockBit ransomware. Indicted in D.N.J. in May 2024 with a $10 million State Department reward.
Mikhail Vasiliev Canadian and Russian pleaded Pending None High-profile LockBit affiliate arrested in Ontario, Canada, with firearms and cryptocurrency recovery.
Ruslan Magomedovich Astamirov Russian Federation charged Pending None Arrested in Arizona in June 2023 for carrying out LockBit attacks against victims in Florida, Japan, and France.
Artur Sungatov Russian Federation fugitive Pending None LockBit affiliate indicted in D.N.J. in February 2024 for targeting manufacturing and insurance firms.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1486 Data Encrypted for Impact
Impact
"LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal." Indictment ¶ 12, Page 6 reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts." Indictment ¶ 18, Page 9 reviewed
T1490 Inhibit System Recovery
Impact
"The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery." Indictment ¶ 14, Page 7 reviewed
T1190 Exploit Public-Facing Application
Initial Access
"Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances." CISA Advisory AA23-325A reviewed
T1047 Windows Management Instrumentation
Execution
"LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets." CISA Advisory AA23-165A ¶ 12 reviewed
T1562.001 Disable or Modify Tools
Defense Evasion
"LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption." Indictment ¶ 21, Page 11 reviewed
T1558.003 Kerberoasting
Credential Access
"LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking." CISA Advisory AA23-165A Appendix reviewed
T1573 Encrypted Channel
Command and Control
"C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443." Indictment ¶ 15, Page 8 reviewed
View 1 Proposed / Unverified Mapping Candidates
T1078: Valid Accounts Proposed by rule

"Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals."

OFAC Sanctions Designations

Dmitry Yuryevich Khoroshev (LockBit Leader) (2024-05-07)

State Department offers reward of up to $10,000,000 for information leading to the identification or location of Dmitry Khoroshev (aka LockBitSupp).

Treasury Release ↗
Dmitry Yuryevich Khoroshev (2024-05-07)

Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia.

Treasury Release ↗
Mikhail Vasiliev (2024-02-20)

Designated LockBit ransomware affiliate extradited from Canada.

Treasury Release ↗

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Khoroshev et al. (LockBit Ransomware Operation), No. 2:24-cr-00330 (U.S. District Court for the District of New Jersey 2024), https://cybercaselibrary.com/cases/lockbit-ransomware-takedown/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/lockbit-ransomware-takedown" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>