{
  "id": "case-lockbit-takedown",
  "slug": "lockbit-ransomware-takedown",
  "title": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation)",
  "summary": "Comprehensive global law enforcement takedown (Operation Cronos) of LockBit ransomware infrastructure, unmasking creator Dmitry Khoroshev (LockBitSupp) and multiple active affiliates who extorted over $500 million from thousands of victims.",
  "case_number": "2:24-cr-00330",
  "court": "U.S. District Court for the District of New Jersey",
  "district": "D.N.J.",
  "country": "United States",
  "opened_at": "2024-05-07",
  "status": "charged",
  "victim_sector": "Healthcare, Education, Manufacturing, Government, Financial Services",
  "victim_country": "United States, United Kingdom, France, Germany, Japan",
  "loss_amount_usd": 500000000,
  "loss_amount_note": "Extorted more than $500 million in ransom payments and caused billions in remediation costs across 2,500 victims.",
  "first_seen_at": "2019-09-01T00:00:00Z",
  "last_updated_at": "2026-09-18T10:00:00Z",
  "actor_slug": "lockbit-group",
  "defendant_slugs": [
    "dmitry-khoroshev",
    "mikhail-vasiliev",
    "ruslan-astamirov",
    "artur-sungatov"
  ],
  "cves": [
    "CVE-2023-4966",
    "CVE-2023-38831"
  ],
  "techniques": [
    {
      "technique_id": "T1486",
      "evidence_excerpt": "LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal.",
      "evidence_locator": "Indictment \u00b6 12, Page 6",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts.",
      "evidence_locator": "Indictment \u00b6 18, Page 9",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    },
    {
      "technique_id": "T1490",
      "evidence_excerpt": "The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery.",
      "evidence_locator": "Indictment \u00b6 14, Page 7",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-165A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
      "technique_name": "Inhibit System Recovery",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances.",
      "evidence_locator": "CISA Advisory AA23-325A",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-325A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals.",
      "evidence_locator": "Complaint \u00b6 22",
      "mapping_status": "proposed",
      "mapped_by": "rule",
      "source_title": "U.S. v. Astamirov Complaint",
      "source_url": "https://www.justice.gov/opa/pr/russian-national-arrested-connection-lockbit-ransomware-attacks",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1047",
      "evidence_excerpt": "LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets.",
      "evidence_locator": "CISA Advisory AA23-165A \u00b6 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA23-165A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
      "technique_name": "Windows Management Instrumentation",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1562.001",
      "evidence_excerpt": "LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption.",
      "evidence_locator": "Indictment \u00b6 21, Page 11",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Disable or Modify Tools",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1558.003",
      "evidence_excerpt": "LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking.",
      "evidence_locator": "CISA Advisory AA23-165A Appendix",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Joint Technical Report",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-165a",
      "technique_name": "Kerberoasting",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1573",
      "evidence_excerpt": "C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443.",
      "evidence_locator": "Indictment \u00b6 15, Page 8",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "Indictment: U.S. v. Khoroshev",
      "source_url": "https://www.justice.gov/opa/pr/us-charges-russian-national-developing-and-operating-lockbit-ransomware",
      "technique_name": "Encrypted Channel",
      "tactic": "Command and Control"
    }
  ],
  "events": [
    {
      "event_type": "arrest",
      "event_date": "2022-11-10",
      "description": "Mikhail Vasiliev arrested in Ontario, Canada, pursuant to U.S. extradition request."
    },
    {
      "event_type": "arrest",
      "event_date": "2023-06-14",
      "description": "Ruslan Astamirov arrested in Arizona on charges of executing LockBit ransomware attacks."
    },
    {
      "event_type": "indictment",
      "event_date": "2024-05-07",
      "description": "Unsealing of 26-count indictment against LockBit creator Dmitry Yuryevich Khoroshev (LockBitSupp)."
    },
    {
      "event_type": "sanction",
      "event_date": "2024-05-07",
      "description": "U.S. Treasury OFAC, UK FCDO, and Australian DFAT impose coordinated sanctions against Khoroshev."
    }
  ]
}