Global Law Enforcement Disrupts LockBit Ransomware Gang
ID: f5d2078b-516c-529a-82aa-a4969aea8593
STIX ID: report--f5d2078b-516c-529a-82aa-a4969aea8593
Feed Name: Dark Reading
Date Published: 2024-02-20
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Global law-enforcement agencies executed Operation Cronos against the LockBit ransomware RaaS operation, seizing its administration environment, public leak site, source code, stolen data, and roughly a thousand decryption keys; authorities cite a PHP vulnerability (CVE-2023-3824) as the vector used to compromise the infrastructure and have arrested suspects and frozen related cryptocurrency accounts. The takedown aims to aid victims and disrupt LockBit affiliates, while agencies (including CISA) published IOCs and recommended mitigations (patching, MFA, access restriction) and warned that such groups can resurface under different names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
