A targeted law enforcement action against the notorious LockBit ransomware gang, dubbed Operation Cronos, caused outages on its affiliated platforms and disrupted its operations. Contrary to LockBit's claims of being back in action, recent research from cybersecurity firm Trend Micro indicates the strike has significantly impacted and undermined the ransomware group's activities.
In a joint operation by U.S., U.K. and other international law enforcement agencies in February, they seized numerous of LockBit’s public-facing websites for its infrastructure connections and control of servers used by its administrators, which disrupts the ability to attack and encrypt networks and extort victims by threatening to publish stolen data.
As one of the world’s most active and destructive ransomware groups, LockBit has targeted over 2,000 victims globally, accumulated more than $120 million in ransom payments and made ransom demands totaling hundreds of millions of dollars, according to the U.S. Department of Justice.
The ransomware-as-a-service (RaaS) group has been in operation since early 2020 and was responsible for 25% to 33% of all ransomware attacks in 2023. LockBit operated using an affiliate model, where the group claimed 20% of ransom payments with the remainder going to affiliates responsible for the ransomware attacks, the Trend Micro research wrote.
Is LockBit back?Trend Micro researchers monitored underground activity to assess the response to Operation Cronos from both LockBit affiliates and other underground threat actors.
Based on the information released on the leak site, LockBitSupp, the persona representing the LockBit ransomware service on cybercrime forums, was banned by two of the most prominent and long-standing cybercrime forums — Exploit and XSS.
In the first 72 hours post-disruption, LockBitSupp attempted to preserve the appearance of being in control of the situation and publicly projected a position of strength to its customer base while also internally trying to rebuild and get back to business, researchers found.
Within a week, LockBitSupp announced its return to new Onion sites on Feb. 24, 2024, and added FBI.gov as the first victim on its new leak site.
“While some saw it as a sign that LockBit operators were back in action, others were a bit more skeptical, with some chat messages discussing how the new leak site is a continuation of the law enforcement operation due to the lack of anything substantial from the FBI leak,” Trend Micro noted.
“While there were a lot of commentaries about how LockBit was back and that the group would come back stronger, evidence to the contrary continued to mount,” researchers added.
Trend Micro reviews LockBit’s activities post-disruptionIn the weeks following Operation Cronos, Trend Micro researchers monitored the vendor’s internal telemetry to gauge the operation’s impact on LockBit and observed a clear drop in the number of actual LockBit infections.
“On the surface, it would appear that LockBit is operating as it had before the disruption, but an examination of the leak site victims and its results paint a very different picture,” they wrote.
By the time of the report, 95 victims were posted to LockBit’s leak site after Operation Cronos and more than two-thirds of the victims were re-uploaded and the attacks on these victims occurred prior to the disruption. They also found in March, several victims being posted to the LockBit leak site were recently posted by other groups such as ALPHV and RansomHub.
The research also highlighted that LockBit appears to be attempting to inflate the apparent victim count and focuses on posting victims from countries whose law enforcement agencies participated in the disruption. “This is possibly an attempt to reinforce the narrative that it would come back stronger and target those responsible for its disruption,” researchers wrote.
The lesson gained from Operation CronosAs the dust continues to settle, Operation Cronos provides a potential blueprint for combating ransomware threats through patient and multinational efforts collaborated among multiple law enforcement agencies and trusted partners in the cybersecurity industry.
“In its spearheading of this new multilayered disruption approach, the NCA [UK’s National Crime Agency] and its partners have a set a new standard on how such operations can be carried out in the future,” Trend Micro wrote.
Other high-profile takedowns, such as the ones against the Emotet and Qakbot only very successful in the short term, and the groups re-emerged after a few months.
However, researchers pointed out that it’s harder for RaaS groups to rebuild. “Reputation and trust are key to attracting affiliates, and when these are lost, it’s harder to get people to return. That’s probably why we see groups rebranding rather than re-emerging under the same name. Another factor is the sheer availability of other groups to join.”
“Operation Cronos succeeded in striking against one element of its business that was most important: its brand,” they added.
Comments