In a coordinated effort named Operation Cronos, law enforcement agencies from various countries, including the U.S. Department of Justice (DOJ) and Europol, have targeted LockBit, one of the prominent ransomware operator groups. This operation resulted in the freezing of over 200 cryptocurrency accounts associated with LockBit’s activities.
Europol disclosed that two LockBit actors were apprehended in Poland and Ukraine, while two more defendants, believed to be affiliates, were arrested and charged in the U.S. Furthermore, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) blacklisted 10 bitcoin and ether addresses linked to the group.
According to data from Arkham Intelligence, some of the OFAC-listed addresses were connected to deposit accounts on platforms like KuCoin, Coinspaid, and Binance. These measures effectively prohibit U.S. entities from offering financial services to the individuals or addresses listed by OFAC.
LockBit, accused of pilfering over $120 million from victims worldwide, operates on a “Ransomware-as-a-Service” (RaaS) model. This entails the development and dissemination of ransomware tools to affiliates who execute attacks, often targeting municipal entities and private companies.
Authorities have also seized LockBit’s website and various pages, impeding their operations and communication channels. Additionally, decryption keys are being distributed to victims, offering them the opportunity to unlock their files without paying ransoms. Law enforcement agencies have recovered more than 1,000 decryption keys designated for victims of LockBit’s attacks and will be reaching out to aid them in data recovery.
Graeme Biggar, director general of the NCA, commented on the collaboration, stating, “Through our close collaboration, we have hacked the hackers; taken control of their infrastructure, seized their source code, and obtained keys that will help victims decrypt their systems.”
