ZeroFox Intelligence Flash Report - LockBit & ALPHV Activity Likely Consistent with Exit Scams
|by Alpha Team

ZeroFox Intelligence Flash Report - LockBit & ALPHV Activity Likely Consistent with Exit Scams
Product Serial: F-2024-03-04a
TLP:CLEAR
In this flash report, ZeroFox researchers provide analysis of LockBit and ALPHV ransomware and digital extortion (R&DE) operators both exhibiting behavior likely consistent with imminent exit scams against their affiliates.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- As of March 4, 2024, operators behind both the LockBit and ALPHV ransomware and digital extortion (R&DE) operations are exhibiting behavior likely consistent with imminent exit scams against their affiliates.
- Both operations have claimed to be continuing operations following recent law enforcement (LE) activities, consistently downplaying the impact of disruptive action despite a significant reduction in observed activity.
- While ZeroFox can neither confirm nor deny the veracity of claims of scamming made by alleged LockBit and ALPHV affiliates, similar activity has been conducted by other notable ransomware collectives in the days preceding the cessation of their operations.
- Victims of outstanding or ongoing extortion attacks by LockBit and ALPHV are unlikely able to assume their stolen data will be deleted following payment of ransom demands. Regardless of whether they choose to pay ransom demands, victims are at an increased risk of stolen data not being deleted and, instead, sold on the deep and dark web (DDW) to the highest bidders.
Tags: tlp:clear, threat actor, all industries, DDW Ransomware