logo

LockBit Ransomware's Darknet Domains Seized in Global Law Enforcement Raid

ID: 8f2da4fa-9137-5a93-a206-c94683f33f25

STIX ID: report--8f2da4fa-9137-5a93-a206-c94683f33f25

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-02-20

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

An international law enforcement operation named Operation Cronos seized multiple darknet domains and infrastructure linked to the prolific LockBit ransomware gang, claiming possession of source code, victim lists, extortion amounts, chats, and decryption keys; authorities across 11 countries and Europol participated, citing exploitation of a critical PHP vulnerability (CVE-2023-3824) to take down the sites. The report notes LockBit's extensive impact since 2019 (thousands of victims and tens of millions extorted), subsequent arrests, frozen crypto accounts, and offers by U.S. authorities for information—while also observing that LockBit briefly re-emerged with new infrastructure and additional victims shortly after the seizure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.