ZeroFox Intelligence Brief - LockBit Update: What Comes Next for the Extortion Collective?
|by Alpha Team

ZeroFox Intelligence Brief - LockBit Update: What Comes Next for the Extortion Collective?
Product Serial: B-2024-05-15a
TLP:CLEAR
In this Intelligence Brief, ZeroFox researchers report on LockBit's inability to maintain stability and retain credibility following recent law enforcement disruption, the unmasking of LockBitSupp, as well as exploring the group's future prospects.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Increased pressure on LockBit’s leadership following recent law enforcement (LE) activity is likely to make the extortion operation more volatile and unpredictable in the short term and may have negative consequences for extortion victims.
- LockBit’s ability to persuade other ransomware and digital extortion (R&DE) threat actors that one of its operation’s purported leadership figures, “LockBitSupp,” was incorrectly identified and that its affiliates’ identities remain secure is very likely hindered by recent reputational damage and degraded credibility.
- LockBit’s inability to maintain stable infrastructure will likely be perceived by many threat actors as evidence that LockBit’s operation is on a declining trajectory and is indicative of its leadership focusing on brand restoration rather than operational efficacy.
- Should barriers persist and hinder LockBit’s ability to restore its reputation—as well as continued degradation in operational output—the likelihood that leadership will seek to close down LockBit’s operation will increase.
- R&DE operations of this nature have a history of ceasing activity via exit scams conducted by the operations’ leadership teams.
Tags: tlp:clear, DDW Ransomware, DDW Markets, threat actor