An overview of the enforcement action against LockBit
On February 20, 2024, a coalition of international agencies led by the National Crime Agency (NCA) of the UK took enforcement action against LockBit, a ransomware as a service (RaaS) operator that manages and distributes ransomware of the same name. As part of Operation Cronos, the coalition seized eight darknet websites belonging to LockBit, and more crucially, the central administration environment, which included a panel from where affiliates staged their attacks. When this panel was live, it was where affiliates modified RaaS samples, managed victims, and even published blog posts. With the central administration environment in the hands of authorities, the ability of LockBit and its affiliates to launch attacks has effectively been dismantled.