Berliner Boersenzeitung - 'Kisses from Prague': The fall of a Russian ransomware giant

EUR -
AED 4.191669
AFN 79.696427
ALL 98.136438
AMD 437.041702
ANG 2.042477
AOA 1046.528897
ARS 1355.256036
AUD 1.758723
AWG 2.054256
AZN 1.939744
BAM 1.954128
BBD 2.303984
BDT 139.480623
BGN 1.955312
BHD 0.430275
BIF 3397.692032
BMD 1.141253
BND 1.467661
BOB 7.884732
BRL 6.377095
BSD 1.141103
BTN 97.702546
BWP 15.265992
BYN 3.734284
BYR 22368.563515
BZD 2.292096
CAD 1.562661
CDF 3287.950775
CHF 0.938179
CLF 0.027666
CLP 1061.6504
CNY 8.189617
CNH 8.199511
COP 4686.271119
CRC 581.690019
CUC 1.141253
CUP 30.243211
CVE 110.170709
CZK 24.756045
DJF 203.19692
DKK 7.458798
DOP 67.372338
DZD 150.029471
EGP 56.636525
ERN 17.118799
ETB 155.813109
FJD 2.566964
FKP 0.840269
GBP 0.842553
GEL 3.115747
GGP 0.840269
GHS 11.695735
GIP 0.840269
GMD 80.464812
GNF 9892.533321
GTQ 8.770494
GYD 239.089282
HKD 8.955073
HNL 29.762527
HRK 7.529879
HTG 149.633089
HUF 403.067624
IDR 18608.590589
ILS 3.988601
IMP 0.840269
INR 97.839012
IQD 1495.120378
IRR 48046.761684
ISK 144.15106
JEP 0.840269
JMD 182.273998
JOD 0.809137
JPY 164.603199
KES 147.518173
KGS 99.80256
KHR 4578.199135
KMF 491.311896
KPW 1027.099105
KRW 1551.499821
KWD 0.349943
KYD 0.950903
KZT 582.081816
LAK 24635.166673
LBP 102240.586823
LKR 341.426289
LRD 227.641287
LSL 20.264157
LTL 3.369824
LVL 0.690333
LYD 6.214681
MAD 10.444861
MDL 19.666377
MGA 5147.602038
MKD 61.465967
MMK 2396.083372
MNT 4084.248117
MOP 9.22183
MRU 45.321211
MUR 52.052675
MVR 17.581002
MWK 1978.625142
MXN 21.828939
MYR 4.828078
MZN 72.982992
NAD 20.264157
NGN 1780.491799
NIO 42.00405
NOK 11.522572
NPR 156.354866
NZD 1.893159
OMR 0.438808
PAB 1.141103
PEN 4.137759
PGK 4.690985
PHP 63.635716
PKR 321.901785
PLN 4.287175
PYG 9111.202035
QAR 4.162238
RON 5.044226
RSD 117.120001
RUB 90.557708
RWF 1615.106341
SAR 4.280343
SBD 9.518541
SCR 16.746051
SDG 684.752211
SEK 10.957397
SGD 1.468165
SHP 0.896846
SLE 25.849201
SLL 23931.510072
SOS 652.244624
SRD 42.160192
STD 23621.637899
SVC 9.986453
SYP 14838.379133
SZL 20.257662
THB 37.229392
TJS 11.28097
TMT 4.005799
TND 3.384903
TOP 2.672931
TRY 44.7788
TTD 7.721903
TWD 34.182247
TZS 3001.495577
UAH 47.264048
UGX 4131.445937
USD 1.141253
UYU 47.429407
UZS 14582.519323
VES 112.184195
VND 29734.21193
VUV 137.604744
WST 3.138777
XAF 655.26986
XAG 0.031542
XAU 0.00034
XCD 3.084294
XDR 0.818035
XOF 655.396069
XPF 119.331742
YER 277.675536
ZAR 20.27389
ZMK 10272.643264
ZMW 28.270355
ZWL 367.483078
  • JRI

    0.0500

    13.02

    +0.38%

  • RIO

    -0.0930

    59.137

    -0.16%

  • NGG

    -0.1650

    70.835

    -0.23%

  • BCC

    0.3250

    87.835

    +0.37%

  • CMSC

    -0.0900

    22.15

    -0.41%

  • GSK

    0.0750

    41.22

    +0.18%

  • SCS

    0.0600

    10.435

    +0.57%

  • RYCEF

    0.0550

    11.92

    +0.46%

  • RBGPF

    0.4600

    67.96

    +0.68%

  • VOD

    -0.0269

    9.9301

    -0.27%

  • BP

    0.1950

    29.26

    +0.67%

  • BTI

    0.1650

    47.635

    +0.35%

  • AZN

    0.5000

    72.85

    +0.69%

  • BCE

    -0.1750

    21.69

    -0.81%

  • RELX

    -0.0100

    53.76

    -0.02%

  • CMSD

    0.0150

    22.25

    +0.07%

'Kisses from Prague': The fall of a Russian ransomware giant
'Kisses from Prague': The fall of a Russian ransomware giant / Photo: - - NATIONAL CRIME AGENCY/AFP/File

'Kisses from Prague': The fall of a Russian ransomware giant

The sudden fall of a ransomware supplier once described as the world's most harmful cybercrime group has raised questions about Moscow's role in its development and the fate of its founder.

Text size:

LockBit supplied ransomware to a global network of hackers, who used the services in recent years to attacks thousands of targets worldwide and rake in tens of millions of dollars.

Ransomware is a type of malicious software, or malware, that steals data and prevents a user from accessing computer files or networks until a ransom is paid for their return.

LockBit supplied a worldwide network of hackers with the tools and infrastructure to carry out attacks, communicate with victims, store the stolen information and launder cryptocurrencies.

According to the US State Department, between 2020 and early 2024 LockBit ransomware carried out attacks on more than 2,500 victims around the world.

It issued ransom demands worth hundreds of millions of dollars and received at least $150 million in actual ransom payments made in the form of digital currency.

But LockBit was dealt its first devastating blow in February 2024 when the British National Crime Agency (NCA), working with the US FBI and several other nations, announced it had infiltrated the group's network and took control of its services.

Later that year, the NCA announced it had identified LockBit's leader as a Russian named Dmitry Khoroshev (alias LockBitSupp).

The US State Department said it was offering a reward of up to $10 million for information leading to his arrest.

Lockbit, which the NCA said was "once the world's most harmful cybercrime group", sought to adapt by using different sites.

But earlier this year it suffered an even more devastating breach and received a taste of its own medicine.

Its systems were hacked and some of its data stolen in an attack whose origins were mysterious and has, unusually in the cybercrime world, never been claimed.

"Don't do crime. Crime is bad. Xoxo from Prague," said a cryptic message written on the website it had been using.

- 'Others grow back' -

"Lockbit was number one. It was in survival mode and took another hit" with the leak, said Vincent Hinderer, Cyber Threat Intelligence team manager with Orange Cyberdefense.

"Not all members of the group have been arrested. Other, less experienced cybercriminals may join," he added.

However, observations of online chats, negotiations and virtual currency wallets indicate "attacks with small ransoms, and therefore a relatively low return on investment", he said.

A French cyberdefence official, who asked not to be named, said the fall of LockBit in no way represented the end of cybercrime.

"You can draw a parallel with counterterrorism. You cut off one head and others grow back."

The balance of power also shifts fast.

Other groups are replacing LockBit, which analysts said was responsible in 2023 for 44 percent of ransomware attacks worldwide.

"Some groups achieve a dominant position and then fall into disuse because they quit on their own, are challenged or there's a breakdown in trust that causes them to lose their partners," said Hinderer.

"Conti was the leader, then LockBit, then RansomHub. Today, other groups are regaining leadership. Groups that were in the top five or top 10 are rising, while others are falling."

In a strange twist, the LockBit data leak revealed that one of its affiliates had attacked a Russian town of 50,000 inhabitants.

LockBit immediately offered the town decryption software -- an antidote to the poison.

But it did not work, the French official told AFP.

"It was reported to the FSB (security service), who quietly resolved the problem," the official said.

- 'Complicit' -

One thing appears to be clear -- the field is dominated by the Russian-speaking world.

Among the top 10 cybercrime service providers, "there are two Chinese groups", said a senior executive working on cybercrime in the private sector.

"All the others are Russian-speaking, most of them still physically located in Russia or its satellites," said the executive, who also requested anonymity.

It is harder to ascertain what role the Russian state might play -- a question all the more pertinent since Moscow's 2022 invasion of Ukraine.

"We can't say that the groups are sponsored by the Russian state but the impunity they enjoy are enough to make it complicit," argued the French official, pointing to a "porosity" between the groups and the security services.

The whereabouts and status of Khoroshev are also a mystery.

The bounty notice from the US State Department, which said Khoroshev was aged 32, gives his date of birth and passport number but says his height, weight and eye colour are unknown.

His wanted picture shows an intense man with cropped hair and bulging muscular forearms.

"As long as he doesn't leave Russia, he won't be arrested," said the private sector expert. "(But) we're not sure he's alive."

"The Russian state lets the groups do what they want. It's very happy with this form of continuous harassment," he alleged.

In the past, there was some cooperation between Washington and Moscow over cybercrime but all this changed with the Russian invasion of Ukraine.

French expert Damien Bancal cites the case of Sodinokibi, a hacker group also known as REvil, which was dismantled in January 2022.

"The FBI helped the FSB arrest the group. During the arrests, they found gold bars and their mattresses were stuffed with cash," he said.

But since the invasion of Ukraine, "no-one is cooperating with anyone any more".

Asked if the US has questioned Moscow about Khoroshev after the bounty was placed on his head, Kremlin spokesman Dmitry Peskov said: "Unfortunately, I have no information."

(F.Schuster--BBZ)