One of the the largest ransomware outfits in the world has been magnificently trolled by the Swedish police and Europol-

Well well well, how the turntables have…you get the idea. Lockbit, a notorious ransomware syndicate that’s estimated to have extorted more than $120 million of ill-gotten gains from victims worldwide, has been subjected to a successful takedown operation from a group comprising a range of international authorities, including the Swedish police and Europol. 

The best part? Rather than simply lock the dark website down, the investigators took the opportunity to do a bit of trolling of their own.

Not content with merely gaining root access to the ransomware group’s servers, the authorities, operating under the title “Operation Cronos”, decided to have a bit of schadenfreude-inducing fun while they were at it (via Ars Technica). In a series of images displayed on the sites Lockbit previously operated, the investigators not only revealed the extent of the access they had obtained—including control of the main web panel that Lockbit operators used to communicate with their victims—but teased the founder, operating under the name LockbitSupp, in a manner they may well be familiar with.

A page on the main site read “Who is LockbitSupp? The $10m question”, complete with a timer counting down the seconds until their identifying information would be posted. This mirrored a common method of extortion used by Lockbit operators to extort large sums of money from victims, in which they taunted their potential prey and gave them an ebbing timeframe in which to pay up.

Not only that, but the images themselves featured filenames that appear to brag about the extent of the operation’s success, with some highlights including “this_is_really-bad.png” and “doesnt_look_good.png”.

The months-long operation has been regarded as a major victory in the fight against ransomware operators, with 34 servers in the Netherlands, Germany, Finland, France, Sweden, and more taken down once the authorities had had their fun. Two arrests have been made so far, with three international arrest warrants and five indictments also issued by French and US authorities.

Lockbit previously operated as a ransomware-as-a-service operation, where malware was distributed by a core team within the group to various “affiliates” who would then put it to use blackmailing victims into handing over their cash. The group and its operators often made use of encryption tools to lock users’ data, before threatening to leak it while performing DDoS attacks to ramp up the pressure, in a method referred to as triple extortion.

14,000 accounts used by Lockbit are now under the control of law enforcement as a result of the operation, which took a huge amount of cooperation between various agencies to bring to fruition. While Lockbit is far from the only ransomware syndicate operating on the dark web, it was certainly one of the largest, and its takedown may well serve as a warning to others hoping to mimic its success.

Not only are the authorities coming, it seems, but if they make it past your digital walls they may well perform a victory lap over the ashes of your criminal empire, and mock you in the process.

Still, difficult to feel too sorry for them, ey? Beyond the malware itself, shame, embarrassment, and fear were the tools of Lockbit’s trade, and in this case, it seems that just desserts have just been served.

Related Posts

Oracle’s Big Shift- Warren Buffett slashes Berkshire Hathaway’s Apple stake by almost 50%, stirs market jitters

Warren Buffett, the billionaire investor, has left the stock market bewildered by dramatically slashing Berkshire Hathaway’s hefty Apple investment. Two years ago, Buffett referred to Apple as…

Religare Broking expects India Vix may trade range bound ahead of elections- Here are the key levels to watch

By Gaurav Arora The May series Nifty futures is currently trading with a premium of around 65 points. After making record highs, the index has broadly been…

Sebi plans to introduce ‘fast track’ concept for public issuance of debt securities

To deepen the bond market, Sebi is looking to introduce the concept of ‘fast track’ public issuance for debt securities and further reduce the face value of…

Share Market Highlights- Nifty settles above 19650, Sensex above 65990; Bank Nifty adds over 140 points; Realty stocks shine

Share Market News Today | Sensex, Nifty, Share Prices Highlights:  The benchmark domestic indices ended the week’s last trading session in the green following the RBI’s announcement…

Star Wars- The Old Republic's Next Big Expansion Launches This Year, 10th Anniversary Celebrations Planned

2021 marks the 10th anniversary of BioWare’s Star Wars: The Old Republic MMO, and the developer is marking the occasion with a big new expansion and more….

The Texas Chain Saw Massacre Is Adding A Horror Legend In Upcoming DLC

The Texas Chain Saw Massacre is adding another original character to its suite of survivors–or “Victims,” as they’re called in-game. Virginia is the character’s name, and most…