{
  "id": "case-lockbit-takedown",
  "slug": "lockbit-ransomware-takedown",
  "title": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation)",
  "summary": "Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.",
  "case_number": "2:24-cr-00330",
  "court": "U.S. District Court for the District of New Jersey",
  "district": "D.N.J.",
  "country": "United States",
  "opened_at": "2024-05-07",
  "status": "charged",
  "victim_sector": "Healthcare, Education, Manufacturing, Government, Financial Services",
  "victim_country": "United States, United Kingdom, France, Germany, Japan",
  "loss_amount_usd": 500000000,
  "loss_amount_note": "Extorted more than $500 million in ransom payments and caused billions in remediation costs across 2,500 victims.",
  "first_seen_at": "2019-09-01T00:00:00Z",
  "last_updated_at": "2026-09-18T10:00:00Z",
  "actor_slug": "lockbit-group",
  "defendant_slugs": [
    "dmitry-khoroshev",
    "mikhail-vasiliev",
    "ruslan-astamirov",
    "artur-sungatov"
  ],
  "cves": [
    "CVE-2023-4966",
    "CVE-2023-38831"
  ],
  "techniques": [
    {
      "technique_id": "T1486",
      "evidence_excerpt": "LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal.",
      "evidence_locator": "Indictment \u00b6 12, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts.",
      "evidence_locator": "Indictment \u00b6 18, Page 9",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1490",
      "evidence_excerpt": "The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-165A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
      "technique_name": "Inhibit System Recovery",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances.",
      "evidence_locator": "CISA Advisory AA23-325A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-325A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals.",
      "evidence_locator": "Complaint \u00b6 22",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "U.S. v. Astamirov Complaint",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-arrested-connection-lockbit-ransomware-attacks",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1047",
      "evidence_excerpt": "LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets.",
      "evidence_locator": "CISA Advisory AA23-165A \u00b6 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-165A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
      "technique_name": "Windows Management Instrumentation",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1562.001",
      "evidence_excerpt": "LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption.",
      "evidence_locator": "Indictment \u00b6 21, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Disable or Modify Tools",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1558.003",
      "evidence_excerpt": "LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking.",
      "evidence_locator": "CISA Advisory AA23-165A Appendix",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Joint Technical Report",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
      "technique_name": "Kerberoasting",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1573",
      "evidence_excerpt": "C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443.",
      "evidence_locator": "Indictment \u00b6 15, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Encrypted Channel",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2022-11-10",
      "description": "Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request."
    },
    {
      "event_type": "arrest",
      "event_date": "2023-06-14",
      "description": "Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks."
    },
    {
      "event_type": "indictment",
      "event_date": "2024-05-07",
      "description": "Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp)."
    },
    {
      "event_type": "sanction",
      "event_date": "2024-05-07",
      "description": "U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Exploitation of perimeter gateway vulnerabilities (such as Citrix Bleed CVE-2023-4966) and acquisition of compromised corporate VPN logins from Initial Access Brokers (IABs).",
    "blast_radius": "Over 2,500 organizations breached worldwide across 120 countries, including Boeing, the UK Royal Mail, hospitals, and emergency dispatch centers. Extorted more than $500 million in ransom payments before an international coalition of 10 law enforcement agencies seized the infrastructure under Operation Cronos.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Perimeter Vulnerability Exploitation & Broker Credentials",
        "description": "Affiliates leveraged unpatched edge vulnerabilities like Citrix Bleed (CVE-2023-4966) to bypass multifactor authentication, or purchased valid network access tokens directly from dark web access brokers.",
        "technical_artifacts": [
          "CVE-2023-4966",
          "Initial Access Broker logins"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Defense Evasion",
        "title": "BYOVD Endpoint Protection Neutralization",
        "description": "Operatives deployed vulnerable, legitimately signed third-party kernel drivers (Bring Your Own Vulnerable Driver attack) to disable antivirus software and endpoint detection and response (EDR) agents.",
        "technical_artifacts": [
          "Vulnerable signed kernel drivers",
          "EDR termination scripts"
        ],
        "mitre_technique_id": "T1562.001"
      },
      {
        "phase": "High-Speed Exfiltration",
        "title": "StealBit Automated Data Theft",
        "description": "Before encrypting hosts, affiliates launched custom StealBit exfiltration executables, parsing local drives for office documents and intellectual property and parallel-uploading gigabytes of data to offshore servers.",
        "technical_artifacts": [
          "StealBit.exe",
          "Multi-connection FTP/HTTP uploads"
        ],
        "mitre_technique_id": "T1041"
      },
      {
        "phase": "Encryption",
        "title": "Multi-Threaded LockBit 3.0 Black Detonation",
        "description": "LockBit 3.0 executed with command-line passkeys, using multiple CPU threads to encrypt files with AES and ECC algorithms, appending random extension strings and deleting volume shadow copies.",
        "technical_artifacts": [
          "LockBit 3.0 payload",
          "vssadmin delete shadows /all /quiet"
        ],
        "mitre_technique_id": "T1486"
      },
      {
        "phase": "Extortion & Infrastructure Seizure",
        "title": "Automated Tor Panel Extortion & Operation Cronos Takedown",
        "description": "Victims were directed to a private Tor negotiation portal with a countdown clock. In February 2024, the FBI, UK NCA, and Europol executed Operation Cronos, taking over the admin panel and releasing decryption tools.",
        "technical_artifacts": [
          "Tor negotiation portal",
          "Operation Cronos law enforcement splash screen"
        ],
        "mitre_technique_id": "T1490"
      }
    ],
    "defensive_takeaways": [
      "Enable Microsoft Vulnerable Driver Blocklist and Driver Signature Enforcement to thwart BYOVD attacks.",
      "Patch public-facing SSL-VPN and gateway appliances within 24 hours of KEV notification.",
      "Block shadow copy deletion commands (vssadmin, wmic shadowcopy) via endpoint behavioral rules.",
      "Maintain immutable, physically isolated offline backups of Active Directory and critical servers."
    ]
  }
}