logo

LockBit Ransomware Group Resurfaces After Law Enforcement Takedown

ID: 5452d9dc-4406-5c5d-bc41-60cfe73ade7f

STIX ID: report--5452d9dc-4406-5c5d-bc41-60cfe73ade7f

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-02-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes LockBit resurfacing on the dark web with new TOR infrastructure and fresh victim listings shortly after an international takedown used a PHP vulnerability to seize its servers; LockBit operators claim law enforcement compromised parts of their infrastructure and discuss changes to their encryption/decryptor procedures. It also covers the arrest of individuals tied to the SugarLocker ransomware group in Russia, outlines SugarLocker’s RaaS model and alleged criminal activity, and summarizes a timeline of Operation Cronos and related global law enforcement actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.