LockBit down but far from out

This week, we saw a high-profile takedown of the LockBit ransomware group. Or at least, thatโ€™s what youโ€™d be forgiven for thinking, given the media coverage of Operation Cronos. More accurately, we have witnessed the disruption of the worldโ€™s most prolific ransomware group, with the takedown of some of its infrastructure and access to critical data including some encryption keys.

Two alleged members of the group have been arrested, but the criminal kingpin – who goes by the name of LockBitSupp – remains at large, albeit with a multi-million dollar bounty on their head.

Many cybersecurity experts have pointed out that disruption isnโ€™t the same as destruction and warned that itโ€™s unlikely this will be the end of the road for LockBit.

Operation Cronos, led by the UKโ€™s National Crime Agency with FBI assistance, has undoubtedly been a success worth applauding. Indeed, the NCA went so far as to troll the LockBit criminals, replacing information about victims on the LockBit dark web leak site with wanted posters and news about arrests and the operation itself.

Unfortunately, itโ€™s way too early to celebrate the death of LockBit, as high-profile ransomware groups have a habit of rising phoenix-like from the ashes of law enforcement takedowns.

LockBit will be reborn

It’s worth remembering that LockBit itself was born out of other groups.

According to an analysis from Flashpoint, the BlackMatter group (a variant of DarkSide) handed over victim data to LockBit following law enforcement targeting in 2021. In 2022, Evil Corp started using LockBit to โ€œbypass restrictions placed on the group by the US Treasury Departmentโ€™s Office of Foreign Assets Control (OFAC)โ€.

โ€œThis disruption will likely be temporary and minimal at best to the organisation behind LockBit,โ€ says Jon Marler, Cyber Evangelist at VikingCloud. โ€œLockBitโ€™s malware is currently in its third major revision, and without any arrests of the core team that created it, we can only expect more.โ€

Something that a Trend Micro research report published today appears to confirm. โ€œRecently, we came into possession of a sample that we believe represents a new evolution of LockBit: an in-development version of a platform-agnostic malware-in-testing that is different from previous versions.”

The report goes on: “Based on its current developmental state, we are tracking this variant as LockBit-NG-Dev, which we further believe could form the basis of a LockBit 4.0 that the group is almost certainly working on.โ€

As Mark Stockley, a Senior Threat Researcher at Malwarebytes, says: โ€œThe main unanswered question is how much of LockBit group is left intact, and what will they do next. It’s very hard to see the LockBit ‘brand’ surviving this, so I expect it will either rebrand or disperse into other groups in the way that Conti did.โ€

More cybersecurity coverage

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.