U.S. v. Khoroshev et al. (LockBit Ransomware Operation)
Key Facts
- Legal Status: CHARGED in U.S. District Court for the District of New Jersey.
- Primary Target Sector: Healthcare, Education, Manufacturing, Government, Financial Services.
- Documented Financial Loss: $500.0 million.
- 8 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Procedural & Incident Timeline
Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request.
Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks.
Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp).
U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Dmitry Yuryevich Khoroshev | Russian Federation | fugitive | Pending | $10.0 million | Developer and primary administrative operator of LockBit ransomware. Indicted in D.N.J. in May 2024 with a $10 million State Department reward. |
| Mikhail Vasiliev | Canadian and Russian | pleaded | Pending | None | High-profile LockBit affiliate arrested in Ontario, Canada, with firearms and cryptocurrency recovery. |
| Ruslan Magomedovich Astamirov | Russian Federation | charged | Pending | None | Arrested in Arizona in June 2023 for carrying out LockBit attacks against victims in Florida, Japan, and France. |
| Artur Sungatov | Russian Federation | fugitive | Pending | None | LockBit affiliate indicted in D.N.J. in February 2024 for targeting manufacturing and insurance firms. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1486 | Data Encrypted for Impact Impact | "LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal." | Indictment ¶ 12, Page 6 | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts." | Indictment ¶ 18, Page 9 | reviewed |
| T1490 | Inhibit System Recovery Impact | "The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery." | Indictment ¶ 14, Page 7 | reviewed |
| T1190 | Exploit Public-Facing Application Initial Access | "Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances." | CISA Advisory AA23-325A | reviewed |
| T1047 | Windows Management Instrumentation Execution | "LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets." | CISA Advisory AA23-165A ¶ 12 | reviewed |
| T1562.001 | Disable or Modify Tools Defense Evasion | "LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption." | Indictment ¶ 21, Page 11 | reviewed |
| T1558.003 | Kerberoasting Credential Access | "LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking." | CISA Advisory AA23-165A Appendix | reviewed |
| T1573 | Encrypted Channel Command and Control | "C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443." | Indictment ¶ 15, Page 8 | reviewed |
View 1 Proposed / Unverified Mapping Candidates
"Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals."
OFAC Sanctions Designations
State Department offers reward of up to $10,000,000 for information leading to the identification or location of Dmitry Khoroshev (aka LockBitSupp).
Treasury Release ↗Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia.
Treasury Release ↗Designated LockBit ransomware affiliate extradited from Canada.
Treasury Release ↗