CASE DOSSIER charged

U.S. v. Khoroshev et al. (LockBit Ransomware Operation)

Docket: 2:24-cr-00330 Court: U.S. District Court for the District of New Jersey Opened: 2024-05-07 Sector: Healthcare, Education, Manufacturing, Government, Financial Services

Key Facts

Status
CHARGED
Legal disposition
Loss Amount
$500.0 million
Extorted more than $500 million in ransom payments and caused billions in remediation costs across 2,500 victims.
Techniques
8
Verified mappings
Defendants
4
Named in charges
  • Legal Status: CHARGED in U.S. District Court for the District of New Jersey.
  • Primary Target Sector: Healthcare, Education, Manufacturing, Government, Financial Services.
  • Documented Financial Loss: $500.0 million.
  • 8 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.

Procedural & Incident Timeline

2022-11-10 arrest

Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request.

2023-06-14 arrest

Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks.

2024-05-07 indictment

Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp).

2024-05-07 sanction

U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Dmitry Yuryevich Khoroshev Russian Federation fugitive Pending $10.0 million Developer and primary administrative operator of LockBit ransomware. Indicted in D.N.J. in May 2024 with a $10 million State Department reward.
Mikhail Vasiliev Canadian and Russian pleaded Pending None High-profile LockBit affiliate arrested in Ontario, Canada, with firearms and cryptocurrency recovery.
Ruslan Magomedovich Astamirov Russian Federation charged Pending None Arrested in Arizona in June 2023 for carrying out LockBit attacks against victims in Florida, Japan, and France.
Artur Sungatov Russian Federation fugitive Pending None LockBit affiliate indicted in D.N.J. in February 2024 for targeting manufacturing and insurance firms.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1486 Data Encrypted for Impact
Impact
"LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal." Indictment ¶ 12, Page 6 reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts." Indictment ¶ 18, Page 9 reviewed
T1490 Inhibit System Recovery
Impact
"The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery." Indictment ¶ 14, Page 7 reviewed
T1190 Exploit Public-Facing Application
Initial Access
"Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances." CISA Advisory AA23-325A reviewed
T1047 Windows Management Instrumentation
Execution
"LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets." CISA Advisory AA23-165A ¶ 12 reviewed
T1562.001 Disable or Modify Tools
Defense Evasion
"LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption." Indictment ¶ 21, Page 11 reviewed
T1558.003 Kerberoasting
Credential Access
"LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking." CISA Advisory AA23-165A Appendix reviewed
T1573 Encrypted Channel
Command and Control
"C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443." Indictment ¶ 15, Page 8 reviewed
View 1 Proposed / Unverified Mapping Candidates
T1078: Valid Accounts Proposed by rule

"Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals."

OFAC Sanctions Designations

Dmitry Yuryevich Khoroshev (LockBit Leader) (2024-05-07)

State Department offers reward of up to $10,000,000 for information leading to the identification or location of Dmitry Khoroshev (aka LockBitSupp).

Treasury Release ↗
Dmitry Yuryevich Khoroshev (2024-05-07)

Developer and key leader of the LockBit ransomware group, designated in coordination with the UK and Australia.

Treasury Release ↗
Mikhail Vasiliev (2024-02-20)

Designated LockBit ransomware affiliate extradited from Canada.

Treasury Release ↗

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, U.S. v. Khoroshev et al. (LockBit Ransomware Operation), No. 2:24-cr-00330 (U.S. District Court for the District of New Jersey 2024), https://cyberattackcaselibrary.pages.dev/cases/lockbit-ransomware-takedown/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/lockbit-ransomware-takedown" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>