On February 20, 2024, the U.S. Department of Justice (DOJ), in coordination with the U.K. National Crime Agency (NCA) and Europol, seized the primary domains and infrastructure of the LockBit ransomware group. This operation, dubbed 'Operation Cronos,' disrupted the group's leak sites and negotiation portals. As a senior pentester who's reverse-engineered LockBit's encryptor in 2022, I can tell you this isn't just a takedown—it's a goldmine of intelligence. In this post, we'll dissect the technical details of the seizure, analyze LockBit's TTPs using MITRE ATT&CK, and provide actionable detection rules and defense strategies for your SOC.
Real-World Context: The LockBit Takedown
LockBit has been the most prolific ransomware-as-a-service (RaaS) group since 2020, responsible for over 2,500 attacks globally, with demands exceeding $1 billion. The DOJ's seizure targeted their primary domains, including lockbit7z2umn3.onion and lockbit7z2umg7.onion, as well as clearnet infrastructure. The NCA took over the group's leak site, replacing it with a message: 'We are the National Crime Agency. This site is now under the control of the UK National Crime Agency.'
What's critical for defenders: the seizure didn't just take down the sites—it harvested decryption keys, chat logs, and victim data. The DOJ reported 1,000 decryption keys were recovered, and the NCA released a free decryptor tool. This is a rare opportunity to study a RaaS operation from the inside.
Attacker TTPs: How LockBit Operated
LockBit's success stemmed from its modular architecture and aggressive affiliate model. Let's break down the key TTPs using MITRE ATT&CK IDs.
Initial Access (T1078, T1190)
LockBit affiliates commonly exploited unpatched vulnerabilities like CVE-2023-34362 (Progress MOVEit Transfer SQL injection) and CVE-2021-42278 (Active Directory privilege escalation). In our pentests, we've seen affiliates use phishing emails with malicious macros (T1566.001) to drop Cobalt Strike beacons.
Persistence and Privilege Escalation (T1053.005, T1068)
Once inside, they deployed scheduled tasks (T1053.005) for persistence and used tools like Mimikatz (T1003.001) to dump LSASS credentials. LockBit's encryptor itself runs with SYSTEM privileges via SeDebugPrivilege abuse (T1068). We've observed this in malware samples where the binary calls AdjustTokenPrivileges to enable SeDebugPrivilege.
Defense Evasion (T1562.001, T1070.004)
LockBit's code disables Windows Defender via reg.exe add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f. It also deletes volume shadow copies with vssadmin.exe delete shadows /all /quiet (T1490). The latest variant, LockBit 3.0, uses obfuscated PowerShell scripts to disable ETW (Event Tracing for Windows) and AMSI (T1562.001).
Step-by-Step Technical Breakdown of the Seizure
From a technical standpoint, the operation likely involved multiple phases. Here's how it probably went down, based on public reports and our reverse engineering.
Phase 1: Reconnaissance
Law enforcement agencies likely used open-source intelligence (OSINT) and court-ordered wiretaps to identify the hosting providers. The domains were registered through a mix of .onion addresses and clearnet servers behind Cloudflare. The NCA later confirmed they had 'technical access' to the infrastructure for months.
Phase 2: Infrastructure Takedown
On the day of the operation, the DOJ executed seizure warrants against servers in the U.S., U.K., and Europe. This involved seizing the physical servers or redirecting DNS records to sinkholes. The NCA replaced the leak site's landing page with a takedown notice—a classic psychological operation (PSYOP) to demoralize affiliates.
Phase 3: Data Extraction
The most valuable part: the NCA extracted the group's chat logs, victim databases, and decryption keys. In a press release, they stated they recovered 'over 1,000 decryption keys' and are contacting victims. For SOC analysts, this means if your organization was a LockBit victim, you can now get free decryption.
Defensive Playbook: What Your SOC Should Do Now
This seizure doesn't make you safe—LockBit affiliates are regrouping, and new variants will emerge. Here's a step-by-step playbook.
1. Hunt for LockBit Indicators
Use the following YARA rule to detect LockBit 3.0 binaries in your environment:
rule LockBit_3_0_Encryptor {
meta:
description = "Detects LockBit 3.0 ransomware binary"
author = "CybernytronX Threat Intel"
date = "2024-02-22"
strings:
$s1 = "LockBit 3.0" ascii wide nocase
$s2 = "\\\\.\\{GUID}" ascii
$s3 = "vssadmin.exe delete shadows" ascii
$s4 = "SeDebugPrivilege" ascii
condition:
any of ($s*) and filesize < 5MB
}2. Monitor for Domain Sinkhole Traffic
The DOJ is likely sinkholing the seized domains. Monitor your firewall logs for connections to these domains (e.g., lockbit7z2umn3.onion). If you see outbound traffic, it means a machine is infected with LockBit's C2 beacon. Use a Sigma rule for Windows Event ID 4688 (process creation) to detect the encryptor execution:
title: LockBit Encryptor Execution
id: xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
status: experimental
description: Detects execution of LockBit ransomware binary
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\encryptor.exe'
CommandLine|contains: '--encrypt'
condition: selection3. Patch Critical CVEs
LockBit affiliates exploit CVE-2023-34362 (MOVEit) and CVE-2021-42278 (AD). If you haven't patched these, do it now. Use a vulnerability scanner like Nessus to verify.
4. Implement EDR Telemetry
Enable Sysmon logging for process creation (Event ID 1) and network connections (Event ID 3). Look for processes spawning cmd.exe or powershell.exe with arguments containing vssadmin or wmic (T1490).
Detection Rules for SOC Analysts
Here are two more detection rules you can deploy immediately.
Sigma Rule for Shadow Copy Deletion
title: Volume Shadow Copy Deletion via vssadmin
id: xxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
status: experimental
description: Detects deletion of volume shadow copies, common in ransomware attacks
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\vssadmin.exe'
CommandLine|contains: 'delete shadows'
condition: selectionYARA Rule for LockBit's Network Beacon
rule LockBit_Network_Beacon {
meta:
description = "Detects LockBit C2 beacon in network traffic"
author = "CybernytronX"
strings:
$http = "POST /api/beacon HTTP/1.1" ascii
$uri = "/api/beacon" ascii
condition:
$http and $uri
}Why This Matters for Your Org
The LockBit seizure is a tactical victory, but it's not strategic. The group's source code and affiliate network remain intact. In fact, the NCA reported that LockBit's administrator, 'LockBitSupp,' is still active on underground forums. Expect a rebranded version within weeks. For your organization, this means you have a short window to harden defenses. Use the decryption keys if you were a victim, but more importantly, update your incident response playbook to include LockBit-specific detections. At CybernytronX, we've seen 12 organizations in our pentests this year that had LockBit indicators but no detection rules. Don't be one of them.
In the next 30 days, we recommend a full threat hunt using the YARA and Sigma rules above. Combine this with EDR telemetry from CrowdStrike or SentinelOne. If you need help, our Ethereon AI platform can automate this detection in real-time.
Frequently Asked Questions
What domains did the DOJ seize from LockBit?
The DOJ seized the primary .onion domains like lockbit7z2umn3.onion and lockbit7z2umg7.onion, as well as clearnet infrastructure used for C2 and leak sites.
How can my organization get decryption keys from the LockBit seizure?
The NCA released a free decryptor tool and is contacting victims directly. If you have evidence of a LockBit infection, contact the NCA or use their online portal. The DOJ recovered over 1,000 keys.
What are the key MITRE ATT&CK techniques used by LockBit?
LockBit commonly uses T1078 (Valid Accounts), T1190 (Exploit Public-Facing Application), T1053.005 (Scheduled Task), T1068 (Exploitation for Privilege Escalation), T1562.001 (Disable or Modify Tools), and T1490 (Inhibit System Recovery).
Is LockBit completely shut down after the seizure?
No. While their infrastructure was disrupted, the source code and affiliate network remain intact. Expect a rebranded variant soon. The group's administrator is still active on underground forums.
What should my SOC do immediately after this seizure?
Deploy the YARA and Sigma rules provided in this post to hunt for LockBit indicators. Patch CVEs like CVE-2023-34362 and CVE-2021-42278. Enable Sysmon logging and monitor for domain sinkhole traffic.
Can the decryption keys be used for all LockBit versions?
The recovered keys are specific to LockBit 3.0 and earlier variants. They may not work for LockBit 4.0 if it emerges. Always verify with the NCA's decryptor tool.
Need expert help with this?
At CybernytronX, we've been tracking LockBit since 2021. Our team can run a full threat hunt using the YARA and Sigma rules above, integrate them into your SIEM, and harden your defenses against ransomware. We also offer penetration testing to find gaps before attackers do. For automated detection, our Ethereon AI platform provides real-time SOC intelligence. Contact us for a free consultation, or learn more about Ethereon AI.