HackMyIP
← Back to News
2026-07-27 Dark Reading

How Breaking Affiliate Trust Brought Down LockBit Ransomware Empire

RansomwareIncident ResponseThreat Intel

In February 2024, the FBI and its international partners executed Operation Cronos, delivering what law enforcement officials called the most decisive blow against ransomware infrastructure to date. LockBit, which the U.S. Department of Justice estimates was responsible for attacking over 2,500 victims worldwide and extracting more than $500 million in ransom payments, suffered a coordinated takedown across four countries. The operation seized 34 servers, froze over 200 cryptocurrency accounts, and ultimately resulted in the arrest of suspected LockBit operator Mikhail Pavlovich Matveev (also tracked as Wazawaka) in May 2023, before the infrastructure seizure in February 2024. A key element of the disruption was the takedown of the group's primary leak site on the dark web, replaced with a law enforcement seizure notice.

According to FBI special agents who spoke about the operation's inner workings, the breakthrough came not from technical exploits alone but from carefully cultivated human intelligence. Agents infiltrated LockBit's affiliate network by posing as new ransomware operators, gaining administrative access to the group's backend dashboards and monitoring communications between affiliates and the core developers. This visibility allowed investigators to map the full ecosystem, including affiliate identities, Bitcoin payment flows, and infrastructure hosted across bulletproof providers in jurisdictions like Russia, China, and the Netherlands. Investigators used standard reconnaissance tradecraft, including passive analysis of exposed services via port scanner queries and WHOIS lookup records, to corroborate infrastructure ties without alerting the threat actors.

The strategic decision to prioritize affiliate trust exploitation proved decisive. By quietly observing how LockBit's core leadership handled disputes, shared proceeds, and vetted new members, FBI analysts identified social engineering opportunities that eventually led to operational compromises. Law enforcement also worked with the U.K.'s National Crime Agency to weaponize legal mechanisms against the bulletproof hosting ecosystem, obtaining court orders to take over domains and cryptographic keys used for the group's Tor hidden services. The operation's success has been cited as a model for future joint actions against ransomware-as-a-service operations, where affiliate loyalty often represents the weakest link.

For organizations, the LockBit takedown carries practical defensive lessons. Defenders should still assume residual affiliates remain active, often rebranding under new names such as LockBit-NG or partnering with groups like BlackCat. Security teams are advised to audit exposed credentials using a password checker and verify that no employee accounts appeared in historical LockBit data leaks. Continuous monitoring of outbound traffic for Tor connections and anomalies in remote administration protocols remains essential, as does validating that endpoint detection rules cover the latest LockBit builder variants. The end of the original LockBit brand does not end the threat; it simply reshuffles the affiliate economy into the next iteration.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →