The Japan Times - 'Kisses from Prague': The fall of a Russian ransomware giant

EUR -
AED 4.229988
AFN 73.146945
ALL 96.133079
AMD 434.212947
ANG 2.061819
AOA 1056.200947
ARS 1595.729488
AUD 1.676138
AWG 2.073241
AZN 1.95884
BAM 1.9575
BBD 2.319785
BDT 141.322745
BGN 1.968783
BHD 0.434815
BIF 3421.327021
BMD 1.1518
BND 1.483169
BOB 7.988181
BRL 6.046028
BSD 1.151795
BTN 109.176408
BWP 15.880861
BYN 3.428493
BYR 22575.287657
BZD 2.316392
CAD 1.600253
CDF 2628.988678
CHF 0.919315
CLF 0.02693
CLP 1063.36549
CNY 7.961072
CNH 7.958342
COP 4233.211976
CRC 534.857582
CUC 1.1518
CUP 30.52271
CVE 110.369005
CZK 24.518422
DJF 205.093682
DKK 7.472328
DOP 68.558058
DZD 153.334083
EGP 61.736268
ERN 17.277006
ETB 178.048178
FJD 2.580321
FKP 0.866974
GBP 0.867284
GEL 3.086771
GGP 0.866974
GHS 12.620455
GIP 0.866974
GMD 84.656271
GNF 10098.639609
GTQ 8.815384
GYD 241.106739
HKD 9.021621
HNL 30.579896
HRK 7.535884
HTG 150.976542
HUF 389.090264
IDR 19570.240438
ILS 3.616135
IMP 0.866974
INR 108.896278
IQD 1508.830137
IRR 1512601.862779
ISK 143.606561
JEP 0.866974
JMD 181.293527
JOD 0.816578
JPY 183.86078
KES 149.734428
KGS 100.724635
KHR 4612.886352
KMF 492.970864
KPW 1036.623761
KRW 1744.390407
KWD 0.354775
KYD 0.959846
KZT 556.830884
LAK 25050.648874
LBP 103140.830206
LKR 362.813545
LRD 211.358254
LSL 19.777978
LTL 3.400967
LVL 0.696713
LYD 7.352226
MAD 10.765177
MDL 20.230571
MGA 4800.106597
MKD 61.676346
MMK 2417.436221
MNT 4113.24352
MOP 9.293293
MRU 45.987343
MUR 54.017007
MVR 17.795778
MWK 1997.10857
MXN 20.796407
MYR 4.629663
MZN 73.657744
NAD 19.778236
NGN 1591.99517
NIO 42.386262
NOK 11.212362
NPR 174.665914
NZD 2.005595
OMR 0.442792
PAB 1.151815
PEN 4.012185
PGK 4.977258
PHP 69.977059
PKR 321.451413
PLN 4.279935
PYG 7530.377025
QAR 4.199475
RON 5.097752
RSD 117.405319
RUB 93.874992
RWF 1681.924321
SAR 4.322129
SBD 9.262822
SCR 17.163771
SDG 692.232263
SEK 10.889179
SGD 1.482949
SHP 0.864149
SLE 28.276608
SLL 24152.69076
SOS 658.257439
SRD 43.308822
STD 23839.942611
STN 24.520978
SVC 10.077884
SYP 127.305795
SZL 19.775833
THB 37.764652
TJS 11.005823
TMT 4.031301
TND 3.395971
TOP 2.773258
TRY 51.215473
TTD 7.825763
TWD 36.869937
TZS 2977.40446
UAH 50.484891
UGX 4290.85719
USD 1.1518
UYU 46.623733
UZS 14046.382845
VES 538.960062
VND 30332.663288
VUV 137.508177
WST 3.196803
XAF 656.512961
XAG 0.016275
XAU 0.000254
XCD 3.112798
XCG 2.07583
XDR 0.816616
XOF 656.512961
XPF 119.331742
YER 274.819021
ZAR 19.662788
ZMK 10367.582559
ZMW 21.681643
ZWL 370.879256
  • RYCEF

    -0.0400

    14.65

    -0.27%

  • RBGPF

    -13.5000

    69

    -19.57%

  • GSK

    0.5500

    54.39

    +1.01%

  • RIO

    3.0250

    89.665

    +3.37%

  • CMSC

    0.0850

    22.81

    +0.37%

  • NGG

    2.0400

    83.96

    +2.43%

  • RELX

    0.8700

    32.84

    +2.65%

  • BCE

    0.2600

    25.51

    +1.02%

  • CMSD

    -0.0400

    22.62

    -0.18%

  • VOD

    0.3300

    14.82

    +2.23%

  • JRI

    0.1400

    11.94

    +1.17%

  • AZN

    5.6800

    194.1

    +2.93%

  • BP

    0.9290

    47.609

    +1.95%

  • BTI

    0.6850

    58.485

    +1.17%

  • BCC

    0.8550

    75.285

    +1.14%

'Kisses from Prague': The fall of a Russian ransomware giant
'Kisses from Prague': The fall of a Russian ransomware giant / Photo: - - NATIONAL CRIME AGENCY/AFP/File

'Kisses from Prague': The fall of a Russian ransomware giant

The sudden fall of a ransomware supplier once described as the world's most harmful cybercrime group has raised questions about Moscow's role in its development and the fate of its founder.

Text size:

LockBit supplied ransomware to a global network of hackers, who used the services in recent years to attacks thousands of targets worldwide and rake in tens of millions of dollars.

Ransomware is a type of malicious software, or malware, that steals data and prevents a user from accessing computer files or networks until a ransom is paid for their return.

LockBit supplied a worldwide network of hackers with the tools and infrastructure to carry out attacks, communicate with victims, store the stolen information and launder cryptocurrencies.

According to the US State Department, between 2020 and early 2024 LockBit ransomware carried out attacks on more than 2,500 victims around the world.

It issued ransom demands worth hundreds of millions of dollars and received at least $150 million in actual ransom payments made in the form of digital currency.

But LockBit was dealt its first devastating blow in February 2024 when the British National Crime Agency (NCA), working with the US FBI and several other nations, announced it had infiltrated the group's network and took control of its services.

Later that year, the NCA announced it had identified LockBit's leader as a Russian named Dmitry Khoroshev (alias LockBitSupp).

The US State Department said it was offering a reward of up to $10 million for information leading to his arrest.

Lockbit, which the NCA said was "once the world's most harmful cybercrime group", sought to adapt by using different sites.

But earlier this year it suffered an even more devastating breach and received a taste of its own medicine.

Its systems were hacked and some of its data stolen in an attack whose origins were mysterious and has, unusually in the cybercrime world, never been claimed.

"Don't do crime. Crime is bad. Xoxo from Prague," said a cryptic message written on the website it had been using.

- 'Others grow back' -

"Lockbit was number one. It was in survival mode and took another hit" with the leak, said Vincent Hinderer, Cyber Threat Intelligence team manager with Orange Cyberdefense.

"Not all members of the group have been arrested. Other, less experienced cybercriminals may join," he added.

However, observations of online chats, negotiations and virtual currency wallets indicate "attacks with small ransoms, and therefore a relatively low return on investment", he said.

A French cyberdefence official, who asked not to be named, said the fall of LockBit in no way represented the end of cybercrime.

"You can draw a parallel with counterterrorism. You cut off one head and others grow back."

The balance of power also shifts fast.

Other groups are replacing LockBit, which analysts said was responsible in 2023 for 44 percent of ransomware attacks worldwide.

"Some groups achieve a dominant position and then fall into disuse because they quit on their own, are challenged or there's a breakdown in trust that causes them to lose their partners," said Hinderer.

"Conti was the leader, then LockBit, then RansomHub. Today, other groups are regaining leadership. Groups that were in the top five or top 10 are rising, while others are falling."

In a strange twist, the LockBit data leak revealed that one of its affiliates had attacked a Russian town of 50,000 inhabitants.

LockBit immediately offered the town decryption software -- an antidote to the poison.

But it did not work, the French official told AFP.

"It was reported to the FSB (security service), who quietly resolved the problem," the official said.

- 'Complicit' -

One thing appears to be clear -- the field is dominated by the Russian-speaking world.

Among the top 10 cybercrime service providers, "there are two Chinese groups", said a senior executive working on cybercrime in the private sector.

"All the others are Russian-speaking, most of them still physically located in Russia or its satellites," said the executive, who also requested anonymity.

It is harder to ascertain what role the Russian state might play -- a question all the more pertinent since Moscow's 2022 invasion of Ukraine.

"We can't say that the groups are sponsored by the Russian state but the impunity they enjoy are enough to make it complicit," argued the French official, pointing to a "porosity" between the groups and the security services.

The whereabouts and status of Khoroshev are also a mystery.

The bounty notice from the US State Department, which said Khoroshev was aged 32, gives his date of birth and passport number but says his height, weight and eye colour are unknown.

His wanted picture shows an intense man with cropped hair and bulging muscular forearms.

"As long as he doesn't leave Russia, he won't be arrested," said the private sector expert. "(But) we're not sure he's alive."

"The Russian state lets the groups do what they want. It's very happy with this form of continuous harassment," he alleged.

In the past, there was some cooperation between Washington and Moscow over cybercrime but all this changed with the Russian invasion of Ukraine.

French expert Damien Bancal cites the case of Sodinokibi, a hacker group also known as REvil, which was dismantled in January 2022.

"The FBI helped the FSB arrest the group. During the arrests, they found gold bars and their mattresses were stuffed with cash," he said.

But since the invasion of Ukraine, "no-one is cooperating with anyone any more".

Asked if the US has questioned Moscow about Khoroshev after the bounty was placed on his head, Kremlin spokesman Dmitry Peskov said: "Unfortunately, I have no information."

T.Ikeda--JT