Unveiling the Fallout: Operation Cronos’ Impact on LockBit Following Landmark Disruption

April 3, 2024 at 07:27AM Summary: Operation Cronos on Feb. 19, 2024 significantly disrupted LockBit’s ransomware operations, leading to a takeover of its leak site by UK’s NCA. Authorities leveraged the site to cast doubt on LockBit’s promises and distribute information about the group. Fallout from the disruption hinted at the significant impact on the … Read more

Ransomware as a Service and the Strange Economics of the Dark Web

March 27, 2024 at 10:10AM Ransomware evolution in the past months includes LockBit’s blog takedown, BlackCat’s exit, and smaller groups emergence. The ecosystem functions as a complex supply chain with RaaS dominating large groups. Affiliate competition and recent takedowns are shifting the landscape, potentially leading to ecosystem fragmentation. Corporate security recommendations include extensive monitoring, patching … Read more

TeamCity Flaw Leads to Surge in Ransomware, Cryptomining, and RAT Attacks

March 20, 2024 at 07:30AM Multiple threat actors are exploiting security flaws in JetBrains TeamCity software to deploy ransomware, cryptocurrency miners, Cobalt Strike beacons, and a Golang-based remote access trojan. The attacks entail the exploitation of CVE-2024-27198, enabling adversaries to gain administrative control over affected servers. Organizations using TeamCity are urged to update their software … Read more

LockBit Ransomware Hacker Ordered to Pay $860,000 After Guilty Plea in Canada

March 14, 2024 at 10:51AM A 34-year-old Russian-Canadian, Mikhail Vasiliev, received a nearly four-year jail sentence in Canada for his involvement in the LockBit ransomware operation. He pleaded guilty to cyber extortion, mischief, and weapons charges. Vasiliev, described as a “cyber-terrorist,” sought ransom payments from Canadian companies and has been ordered to pay back over … Read more

LockBit Ransomware Affiliate Sentenced to Prison in Canada

March 13, 2024 at 12:51PM Russian-Canadian national Mikhail Vasiliev, 34, sentenced to nearly four years in prison in Canada for his role in LockBit ransomware operation. He targeted at least three organizations in Canada, seeking ransom payments. The US is also pursuing charges against him. LockBit, operating under ransomware-as-a-service model, was a prolific operation until … Read more

LockBit ransomware affiliate gets four years in jail, to pay $860k

March 13, 2024 at 07:46AM Russian-Canadian cybercriminal Mikhail Vasiliev sentenced to 4 years in prison by Ontario court for involvement in LockBit ransomware gang, with restitution of $860,000 to Canadian victims and potential extradition to the U.S. LockBit, a ransomware-as-a-service operation, has faced disruption by law enforcement, but despite relaunching, analysis suggests its activities are … Read more

Ransomware ban backers insist thugs must be cut off from payday

March 4, 2024 at 09:38AM Law enforcement’s crackdown on the LockBit ransomware crew has reignited calls for a ban on ransom payments. Ciaran Martin, CEO of the NCSC, emphasized the need for such a ban due to the devastating impact of ransomware. However, concerns about businesses’ ability to recover without payments and the need for … Read more

The federal bureau of trolling hits LockBit, but the joke’s on us

March 4, 2024 at 04:37AM Operation Cronos, a multinational effort to dismantle ransomware gang LockBit, surprises with a humorous twist as law enforcement tampered with the gang’s website. Despite the takedown, LockBit reappeared, raising concerns about the resilience of criminal organizations and the challenges of combating them, especially in the context of cryptocurrency. This event … Read more

LockBit’s contested claim of fresh ransom payment suggests it’s been well hobbled

March 3, 2024 at 10:20PM LockBit ransomware gang continues operations despite law enforcement takedown, claiming to possess sensitive data. Analyst suggests gang’s posturing to reassure affiliates, while CISA warns Ivanti vulnerabilities could persist even after factory resets. Security researchers raise concerns about potential cloud-based SAML token forgery vulnerability, advising organizations to safeguard certificates against potential … Read more

Georgia’s Largest County Is Still Repairing Damage From January Cyberattack

March 3, 2024 at 08:54AM LockBit hackers disrupted government services in Georgia’s Fulton County by shutting down phone lines and threatening to release stolen data unless officials paid ransom. Despite law enforcement’s efforts to disrupt LockBit, the county is still working to restore services. The cyberattack did not affect the criminal case against former President … Read more