Dubai Telegraph - 'Kisses from Prague': The fall of a Russian ransomware giant

EUR -
AED 4.240257
AFN 73.32143
ALL 96.053795
AMD 433.817139
ANG 2.066822
AOA 1058.764604
ARS 1599.696819
AUD 1.675026
AWG 2.078272
AZN 1.967396
BAM 1.955877
BBD 2.317892
BDT 141.205579
BGN 1.973561
BHD 0.434817
BIF 3418.53506
BMD 1.154596
BND 1.481959
BOB 7.981315
BRL 6.067751
BSD 1.150845
BTN 109.078309
BWP 15.865627
BYN 3.425635
BYR 22630.074075
BZD 2.314491
CAD 1.604715
CDF 2635.36902
CHF 0.917923
CLF 0.027055
CLP 1068.301597
CNY 7.980392
CNH 7.989998
COP 4229.267091
CRC 534.421114
CUC 1.154596
CUP 30.596784
CVE 110.269357
CZK 24.603629
DJF 204.928096
DKK 7.496448
DOP 68.502706
DZD 153.573067
EGP 60.780401
ERN 17.318934
ETB 177.904429
FJD 2.606389
FKP 0.868614
GBP 0.866456
GEL 3.094767
GGP 0.868614
GHS 12.609498
GIP 0.868614
GMD 84.867224
GNF 10090.398654
GTQ 8.807348
GYD 240.899518
HKD 9.036039
HNL 30.555207
HRK 7.557064
HTG 150.85596
HUF 390.276858
IDR 19617.503194
ILS 3.622683
IMP 0.868614
INR 109.435464
IQD 1507.559561
IRR 1516272.693223
ISK 144.047794
JEP 0.868614
JMD 181.147157
JOD 0.818654
JPY 185.066713
KES 149.485906
KGS 100.96983
KHR 4609.182101
KMF 494.167328
KPW 1039.005581
KRW 1741.604016
KWD 0.355512
KYD 0.959038
KZT 556.361981
LAK 25029.988892
LBP 103054.87152
LKR 362.514322
LRD 211.168343
LSL 19.761581
LTL 3.409221
LVL 0.698404
LYD 7.34629
MAD 10.755925
MDL 20.213799
MGA 4796.189489
MKD 61.642435
MMK 2427.526343
MNT 4123.646826
MOP 9.285467
MRU 45.949815
MUR 54.000874
MVR 17.838939
MWK 1995.478838
MXN 20.923702
MYR 4.530678
MZN 73.836825
NAD 19.761581
NGN 1597.337286
NIO 42.351673
NOK 11.20288
NPR 174.524895
NZD 2.015881
OMR 0.443458
PAB 1.150845
PEN 4.008858
PGK 4.973196
PHP 69.911197
PKR 321.19049
PLN 4.298271
PYG 7524.297272
QAR 4.195866
RON 5.111746
RSD 117.404638
RUB 93.863708
RWF 1680.566396
SAR 4.33291
SBD 9.285301
SCR 17.363686
SDG 693.912357
SEK 10.938258
SGD 1.49255
SHP 0.866246
SLE 28.345751
SLL 24211.30527
SOS 657.725986
SRD 43.413994
STD 23897.798134
STN 24.500968
SVC 10.069398
SYP 129.111885
SZL 19.759781
THB 37.518628
TJS 10.995934
TMT 4.041085
TND 3.392934
TOP 2.779989
TRY 51.310654
TTD 7.819309
TWD 36.998328
TZS 2969.117305
UAH 50.443693
UGX 4287.169379
USD 1.154596
UYU 46.58184
UZS 14034.554481
VES 540.268027
VND 30409.162038
VUV 138.27014
WST 3.204592
XAF 655.982917
XAG 0.0165
XAU 0.000256
XCD 3.120353
XCG 2.074082
XDR 0.815832
XOF 655.982917
XPF 119.331742
YER 275.490657
ZAR 19.766689
ZMK 10392.750198
ZMW 21.663856
ZWL 371.779317
  • RBGPF

    -13.5000

    69

    -19.57%

  • CMSD

    -0.0900

    22.66

    -0.4%

  • NGG

    -0.4800

    81.92

    -0.59%

  • GSK

    -0.1000

    53.84

    -0.19%

  • BCE

    -0.2200

    25.25

    -0.87%

  • RIO

    0.8500

    86.64

    +0.98%

  • CMSC

    -0.0500

    22.77

    -0.22%

  • AZN

    5.0200

    188.42

    +2.66%

  • RYCEF

    -0.5900

    14.65

    -4.03%

  • BTI

    0.3749

    57.8

    +0.65%

  • RELX

    -0.1000

    31.97

    -0.31%

  • JRI

    -0.2700

    11.8

    -2.29%

  • BCC

    0.1400

    74.43

    +0.19%

  • VOD

    -0.1400

    14.49

    -0.97%

  • BP

    0.5100

    46.68

    +1.09%

'Kisses from Prague': The fall of a Russian ransomware giant
'Kisses from Prague': The fall of a Russian ransomware giant / Photo: - - NATIONAL CRIME AGENCY/AFP/File

'Kisses from Prague': The fall of a Russian ransomware giant

The sudden fall of a ransomware supplier once described as the world's most harmful cybercrime group has raised questions about Moscow's role in its development and the fate of its founder.

Text size:

LockBit supplied ransomware to a global network of hackers, who used the services in recent years to attacks thousands of targets worldwide and rake in tens of millions of dollars.

Ransomware is a type of malicious software, or malware, that steals data and prevents a user from accessing computer files or networks until a ransom is paid for their return.

LockBit supplied a worldwide network of hackers with the tools and infrastructure to carry out attacks, communicate with victims, store the stolen information and launder cryptocurrencies.

According to the US State Department, between 2020 and early 2024 LockBit ransomware carried out attacks on more than 2,500 victims around the world.

It issued ransom demands worth hundreds of millions of dollars and received at least $150 million in actual ransom payments made in the form of digital currency.

But LockBit was dealt its first devastating blow in February 2024 when the British National Crime Agency (NCA), working with the US FBI and several other nations, announced it had infiltrated the group's network and took control of its services.

Later that year, the NCA announced it had identified LockBit's leader as a Russian named Dmitry Khoroshev (alias LockBitSupp).

The US State Department said it was offering a reward of up to $10 million for information leading to his arrest.

Lockbit, which the NCA said was "once the world's most harmful cybercrime group", sought to adapt by using different sites.

But earlier this year it suffered an even more devastating breach and received a taste of its own medicine.

Its systems were hacked and some of its data stolen in an attack whose origins were mysterious and has, unusually in the cybercrime world, never been claimed.

"Don't do crime. Crime is bad. Xoxo from Prague," said a cryptic message written on the website it had been using.

- 'Others grow back' -

"Lockbit was number one. It was in survival mode and took another hit" with the leak, said Vincent Hinderer, Cyber Threat Intelligence team manager with Orange Cyberdefense.

"Not all members of the group have been arrested. Other, less experienced cybercriminals may join," he added.

However, observations of online chats, negotiations and virtual currency wallets indicate "attacks with small ransoms, and therefore a relatively low return on investment", he said.

A French cyberdefence official, who asked not to be named, said the fall of LockBit in no way represented the end of cybercrime.

"You can draw a parallel with counterterrorism. You cut off one head and others grow back."

The balance of power also shifts fast.

Other groups are replacing LockBit, which analysts said was responsible in 2023 for 44 percent of ransomware attacks worldwide.

"Some groups achieve a dominant position and then fall into disuse because they quit on their own, are challenged or there's a breakdown in trust that causes them to lose their partners," said Hinderer.

"Conti was the leader, then LockBit, then RansomHub. Today, other groups are regaining leadership. Groups that were in the top five or top 10 are rising, while others are falling."

In a strange twist, the LockBit data leak revealed that one of its affiliates had attacked a Russian town of 50,000 inhabitants.

LockBit immediately offered the town decryption software -- an antidote to the poison.

But it did not work, the French official told AFP.

"It was reported to the FSB (security service), who quietly resolved the problem," the official said.

- 'Complicit' -

One thing appears to be clear -- the field is dominated by the Russian-speaking world.

Among the top 10 cybercrime service providers, "there are two Chinese groups", said a senior executive working on cybercrime in the private sector.

"All the others are Russian-speaking, most of them still physically located in Russia or its satellites," said the executive, who also requested anonymity.

It is harder to ascertain what role the Russian state might play -- a question all the more pertinent since Moscow's 2022 invasion of Ukraine.

"We can't say that the groups are sponsored by the Russian state but the impunity they enjoy are enough to make it complicit," argued the French official, pointing to a "porosity" between the groups and the security services.

The whereabouts and status of Khoroshev are also a mystery.

The bounty notice from the US State Department, which said Khoroshev was aged 32, gives his date of birth and passport number but says his height, weight and eye colour are unknown.

His wanted picture shows an intense man with cropped hair and bulging muscular forearms.

"As long as he doesn't leave Russia, he won't be arrested," said the private sector expert. "(But) we're not sure he's alive."

"The Russian state lets the groups do what they want. It's very happy with this form of continuous harassment," he alleged.

In the past, there was some cooperation between Washington and Moscow over cybercrime but all this changed with the Russian invasion of Ukraine.

French expert Damien Bancal cites the case of Sodinokibi, a hacker group also known as REvil, which was dismantled in January 2022.

"The FBI helped the FSB arrest the group. During the arrests, they found gold bars and their mattresses were stuffed with cash," he said.

But since the invasion of Ukraine, "no-one is cooperating with anyone any more".

Asked if the US has questioned Moscow about Khoroshev after the bounty was placed on his head, Kremlin spokesman Dmitry Peskov said: "Unfortunately, I have no information."

I.Mansoor--DT