On the morning of February 20, 2024, anyone visiting LockBit's dark web leak site saw something unexpected: the site itself had been seized. The familiar LockBit interface - where the group published the names of victims and threatened to release stolen data unless ransoms were paid - had been replaced by a law enforcement banner. "This site is now under control of the National Crime Agency of the UK, working in close cooperation with the FBI and the international law enforcement task force Operation Cronos," it read. The group that had been the world's most prolific ransomware operation for three years had been disrupted.

Operation Cronos, coordinated by Europol and Eurojust, involved 10 countries: the UK, US, France, Germany, Switzerland, Australia, Sweden, Netherlands, Japan, and Canada. The operation seized 34 servers, obtained 1,000 decryption keys that were immediately provided to victims, froze 200 cryptocurrency accounts, and arrested two LockBit affiliates in Poland and Ukraine. Five days later, US and UK authorities publicly named LockBit's primary administrator: Dmitry Khoroshev, a 31-year-old from Voronezh, Russia, operating under the alias LockBitSupp. The State Department offered $10 million for his arrest.

What LockBit Was

LockBit had operated as a ransomware-as-a-service (RaaS) operation since at least 2019, with the LockBit 2.0 and 3.0 releases in 2021 and 2022 establishing it as the dominant ransomware brand by market share. Mandiant, Recorded Future, and other threat intelligence firms consistently reported LockBit as responsible for the largest share of ransomware attacks by volume in 2022 and 2023 - estimates ranged from 25% to over 40% of all ransomware incidents in certain periods.

The RaaS model meant that Khoroshev and the core LockBit team did not personally conduct most attacks. They developed and maintained the ransomware itself, operated the leak site, managed the negotiation and payment infrastructure, and handled the cryptocurrency flows. Affiliates - independent criminal operators who paid to use the LockBit platform - conducted the actual intrusions, deploying LockBit after gaining access to victim networks through various means. The core team took approximately 20% of each ransom payment; affiliates kept 80%.

This model had significant implications for both the scale of LockBit's operations and the difficulty of disrupting them. The affiliate network was large - at the time of the takedown, law enforcement estimated LockBit had worked with over 200 affiliates globally. Each affiliate had their own intrusion techniques, initial access brokers, and operational patterns. Disrupting the core infrastructure affected all affiliates simultaneously, but the affiliates themselves - the people actually breaking into networks - could potentially regroup under a different ransomware brand.

[INFO]
The LockBit affiliate model was explicitly designed to balance operator control with affiliate autonomy. The core team maintained brand standards (the distinctive LockBit name, the leak site, the payment portal), handled the technical ransomware development, and processed payments. Affiliates could choose their own targets, set their own ransom amounts within negotiation guidelines, and were specifically prohibited from targeting hospitals, critical infrastructure, and countries in the former Soviet Union - restrictions that were more honored in the breach than the observance, but which provided deniability. Several prominent affiliates were eventually identified and prosecuted independently of the core team.

Operation Cronos: The Technical Execution

The mechanics of how law enforcement seized LockBit's infrastructure have not been fully disclosed, but the operation's scope provides clues. Seizing 34 servers across multiple countries and jurisdictions required either legal process in each country or direct technical compromise of the servers - or both.

The UK National Crime Agency has confirmed that the operation involved gaining access to LockBit's administrator panel, which gave law enforcement visibility into the full LockBit ecosystem: the list of active affiliates, their targets, the negotiation threads with victims, and the decryption keys held for each active attack. The 1,000 decryption keys obtained and distributed to victims came from this administrative access.

NCA also obtained LockBit's source code, affiliate communications, and the data LockBit had claimed to have destroyed after victims paid ransoms - demonstrating that LockBit had lied to paying victims about deleting their data after payment, which the group had committed to as part of its payment guarantee. The law enforcement announcement explicitly highlighted this: victims who paid ransoms had their data retained anyway.

The psychological dimension of the operation was unusually sophisticated. Rather than simply seizing the site and issuing a press release, law enforcement repurposed LockBit's own infrastructure against the group. The seized LockBit admin panel was used to send messages to all LockBit affiliates announcing the operation. The LockBit leak site format - the same format LockBit used to name and shame victims - was used to name and shame LockBit affiliates, revealing their handles and in some cases their identities. A "countdown" timer on the seized site promised the revelation of LockBit's administrator identity at a specified time - then revealed Khoroshev's name, photo, and personal details when the clock ran out.

LockBitSupp: The Unmasking of Dmitry Khoroshev

Khoroshev's identification was the most personally significant part of Operation Cronos. Ransomware administrators go to extraordinary lengths to conceal their identities, and the public naming of a living, identified person with $10 million on their head represented a different kind of deterrence message than infrastructure seizures alone.

LockBitSupp had been active in public-facing communications - answering questions on criminal forums, running a public bounty program offering $1 million to anyone who could identify the administrator (ironic in retrospect), and presenting a confident public persona. The investigation that identified Khoroshev combined traditional financial investigation (tracing cryptocurrency flows), human intelligence, and digital forensics from the seized infrastructure.

Khoroshev was charged by the US Department of Justice with 26 counts, including conspiracy to commit fraud, extortion, and intentional damage to protected computers. The UK and Australian governments also issued sanctions against him. He remains in Russia and is effectively beyond extradition, but the charges and public identification created pressure on his ability to operate internationally and marked the first time a sitting ransomware operator of LockBit's scale had been publicly identified with criminal charges while still free.

[WARNING]
The $10 million State Department reward for Khoroshev under the Rewards for Justice program created an interesting problem: it functioned simultaneously as a genuine law enforcement tool (someone might come forward with information), a deterrence signal (ransomware operators now know they can be publicly identified and have substantial bounties placed on them), and a limitation on Khoroshev's mobility (accepting the reward requires cooperation with US law enforcement, making any international travel potentially dangerous). The program has previously produced results - multiple cybercriminals identified via the program have been arrested in third countries.

LockBit's Response: The Resilience Problem

Four days after the Operation Cronos seizure, LockBit was back. Khoroshev published a lengthy statement on a new dark web site claiming law enforcement had used a PHP vulnerability to compromise his infrastructure, denying that the operation had obtained source code or the full victim list, and announcing that LockBit 4.0 was in development. New victims began appearing on the rebuilt leak site within a week of the takedown.

This rapid reconstitution was embarrassing for law enforcement but not entirely surprising. The fundamental challenge with ransomware infrastructure disruption is that the core asset - the ransomware code and the relationships with affiliates - is not held in a server that can be seized. Khoroshev retained his relationships with affiliates, his knowledge of the ransomware business, and his freedom. Rebuilding a new dark web site and restarting operations was a matter of weeks, not months.

The post-Cronos LockBit operation was, by most assessments, smaller and less active than pre-Cronos. Several affiliates who had been identified did not return. Law enforcement's public reveal of 194 affiliate handles had created concern within the affiliate community about operational security. The brand had been tarnished - victims and the broader criminal community had seen law enforcement occupy LockBit's infrastructure and use it to embarrass the group.

What Operation Cronos Achieved and Didn't

The most concrete achievements of Operation Cronos were the 1,000 decryption keys distributed to victims, the arrests of two affiliates, and the public identification of Khoroshev. The decryption keys had immediate practical value - organizations that had been encrypted and were considering paying ransom instead received free decryptors. Europol established a portal where victims could check whether their decryption key was among those obtained.

The arrests of affiliates - who actually conducted intrusions - had more practical deterrence value than arrests of infrastructure operators alone, because affiliates are the people doing the day-to-day hacking. Each arrested affiliate represents potentially dozens of future attacks that will not occur. The LockBit arrests were a small number relative to the affiliate pool, but each successful affiliate prosecution sends a signal to the others.

What the operation did not achieve was the permanent disruption of LockBit or the arrest of Khoroshev. This was not a failure of the operation specifically - it is a structural limitation of law enforcement action against threat actors in countries that do not extradite to Western jurisdictions. The practical ceiling on operations against Russia-based ransomware operators, absent cooperation from Russian law enforcement (which only materialized briefly around 2021-2022 when diplomatic pressure was highest), is disruption and public exposure rather than arrest and prosecution.

Operation Cronos established a template that subsequent operations have followed: Qakbot (August 2023), ALPHV/BlackCat (December 2023), and ongoing operations against other ransomware infrastructure have all combined server seizures with affiliate identification and attempts to distribute decryption keys. The law enforcement community appears to have concluded that persistent pressure, rapid infrastructure seizure, and affiliate identification - even without core operator arrests - is the most achievable strategy against ransomware groups headquartered in non-cooperative jurisdictions.

[IOC]
LockBit 3.0 indicators: File extension appended to encrypted files: .lockbit or [random-string]. Ransom note file: Restore-My-Files.txt. Uses legitimate Windows tools (wmic, vssadmin, bcdedit) to delete shadow copies before encryption. Known affiliate TTPs for initial access included RDP brute force, VPN vulnerability exploitation (Citrix, Fortinet, Pulse), and phishing. LockBit 3.0 (also called LockBit Black) leaked source code in September 2022, enabling copycat operations by other groups including the Bl00dy and Buhti ransomware groups. Detection: look for shadow copy deletion commands and abnormal SMB file activity indicative of lateral movement before encryption begins.