ZeroFox Intelligence Flash Report - LockBit Disrupted By Law Enforcement Agencies
|by Alpha Team

ZeroFox Intelligence Flash Report - LockBit Disrupted By Law Enforcement Agencies
Product Serial: F-2024-02-20a
TLP:CLEAR
In this flash report, ZeroFox researchers provide updates around a joint international law enforcement effort to disrupt the infrastructure of the LockBit ransomware and digital extortion operation, and what this likely means for the collective's activities.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On February 19, 2024, Ransomware & Digital Extortion (R&DE) collective LockBit’s leak site was seized by law enforcement agencies in a joint operation between 11 countries dubbed “Operation Cronos.”
- LockBit’s affiliate panel source code, chats, and victim information have also reportedly been seized, with a free decryption key released for victims. As many as 22 known LockBit onion site links are either offline or displaying a seizure message. However, some of the collective’s other dark web sites remain operational.
- The apparent success of Operation Cronos is likely to have a significant impact on LockBit’s immediate operational capability and a short-term suppressive effect on the overall R&DE threat, considering the significant proportion of extortion attacks for which LockBit is responsible.
- However, the operation is unlikely to have a sustained impact on the overall threat from R&DE. Comprehensive degradation of LockBit’s infrastructure will likely result in a short cessation in activity from LockBit operatives before they resume operations—either under the LockBit name or an alternative banner. It is crucial security teams continue to monitor for LockBit indicators of compromise (IOCs) and tactics, techniques, and procedures (TTPs).
Tags: tlp:clear, threat actor, all industries, DDW Ransomware