This week, we saw a high-profile takedown of the LockBit ransomware group. Or at least, thatโs what youโd be forgiven for thinking, given the media coverage of Operation Cronos. More accurately, we have witnessed the disruption of the worldโs most prolific ransomware group, with the takedown of some of its infrastructure and access to critical data including some encryption keys.
Two alleged members of the group have been arrested, but the criminal kingpin – who goes by the name of LockBitSupp – remains at large, albeit with a multi-million dollar bounty on their head.
Many cybersecurity experts have pointed out that disruption isnโt the same as destruction and warned that itโs unlikely this will be the end of the road for LockBit.
Operation Cronos, led by the UKโs National Crime Agency with FBI assistance, has undoubtedly been a success worth applauding. Indeed, the NCA went so far as to troll the LockBit criminals, replacing information about victims on the LockBit dark web leak site with wanted posters and news about arrests and the operation itself.
Unfortunately, itโs way too early to celebrate the death of LockBit, as high-profile ransomware groups have a habit of rising phoenix-like from the ashes of law enforcement takedowns.
LockBit will be reborn
It’s worth remembering that LockBit itself was born out of other groups.
According to an analysis from Flashpoint, the BlackMatter group (a variant of DarkSide) handed over victim data to LockBit following law enforcement targeting in 2021. In 2022, Evil Corp started using LockBit to โbypass restrictions placed on the group by the US Treasury Departmentโs Office of Foreign Assets Control (OFAC)โ.
โThis disruption will likely be temporary and minimal at best to the organisation behind LockBit,โ says Jon Marler, Cyber Evangelist at VikingCloud. โLockBitโs malware is currently in its third major revision, and without any arrests of the core team that created it, we can only expect more.โ
Something that a Trend Micro research report published today appears to confirm. โRecently, we came into possession of a sample that we believe represents a new evolution of LockBit: an in-development version of a platform-agnostic malware-in-testing that is different from previous versions.”
The report goes on: “Based on its current developmental state, we are tracking this variant as LockBit-NG-Dev, which we further believe could form the basis of a LockBit 4.0 that the group is almost certainly working on.โ
As Mark Stockley, a Senior Threat Researcher at Malwarebytes, says: โThe main unanswered question is how much of LockBit group is left intact, and what will they do next. It’s very hard to see the LockBit ‘brand’ surviving this, so I expect it will either rebrand or disperse into other groups in the way that Conti did.โ
More cybersecurity coverage