We expected this, but Lockbit is now back and could become more dangerous

Terry Ring, one of the people who participates here on TSB as well as assisting in the Security Hour on Throwback called this one.

I did state that it is possible that he could be right, and we do know there have been at least two arrests during the takedown.

blog post when learning about the takedown

I’m not necessarily surprised at the fact we’re learing two things.

  • They have ongoing wallets of unspent funds
  • the funds range somewhere between 110 and 125 million dollars in today’s exchange rate

Unfortunately, this means that they’ve rebuilt servers and infrastructure and I think they’ll be more dangerous now.

While we enjoyed the respite, I think this was monumental. Even though it didn’t last long, we can celebrate on the fact that we can work together and we can disrupt the infrastructure. Even if it is a short time, they were too busy rebuilding instead of bugging people for money. That was a great win for us, and we should smile at this win.

Following the LockBit takedown in Operation Cronos, the National Crime Agency (NCA) in the U.K. with support from blockchain analysis company Chainalysis identified more than 500 cryptocurrency addresses being active.
LockBit’s money

The article continues:

The investigation found that more than 2,200 BTC – more than $110 million at today’s exchange rate, remained unspent when LockBit was disrupted.

A press release from the NCA today notes that “these funds represent a combination of both victim and LockBit payments” and that a significant part of this money represents the 20% fee that affiliates paid to the ransomware developers.

The work that Chainalysis and others do to disrupt and hopefully take down these groups is tremendous. Chainalysis was talked about in one of the books I recently read, search it out on the blog.

As expected, the article indicates that they did not delete data, even after getting paid. I hardly think actors do this, they want it around if they ever choose to go after the company or individual again. Its precious data to them.

To read more, read the article LockBit ransomware gang has over $110 million in unspent bitcoin coming from Bleeping Computer.

We’ll have to see how bad this is going to get now. Great call, Terry!


Discover more from Jared's Technology podcast network

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.