Ransomware Interviews

CyberSecurityIL

Back to list

LockBit

December 2024
Q:

LockBit is one of the oldest ransomware groups that is still active today, despite prolonged efforts by law enforcement agencies around the world, including Operation Cronos, which generated a lot of media noise. What is the secret?

A:

To remain elusive and undetected, you need to know how to launder ransom payments and not Google anything criminal on your iPhone. That is the whole secret.

Q:

During Operation Cronos, law enforcement agencies reported significant damage to your infrastructure. Can you elaborate a little on the real impact behind the scenes of that operation and its impact on the future of LockBit?

A:

If we are talking about the cost of replacing two servers that were damaged, then the cost of the 'significant' damage caused by the operation was $2,000. The next day I simply bought new servers and continued working. If we are talking about lost profit, then yes, I probably lost some profits, but I do not know how much. It is difficult to measure. Considering that thanks to the sanctions imposed on a person I do not know, the FBI effectively gave me a free hand and forced me to remove all restrictions on attacks against critical infrastructure, allow automatic registration for affiliates for $777, and more. So I am not sure what the NCA actually achieved with their operation and how it will develop in the future. Time will tell.

Q:

Recently, we have seen many new ransomware groups and other groups gaining momentum, such as RansomHub. At the same time, there have been quite a few reports that your affiliates moved to other groups following law enforcement actions. How do you plan to keep your next affiliates and make sure they do not leave for competing groups?

A:

I do not hold anyone by force. Everyone works wherever they want, but let's talk about my advantages over the competitors: 1. I have hundreds of millions of dollars, so there are no scams with me. I will not lie to affiliates. Other groups that see large amounts of money get confused and scam their affiliates. 2. My encryptors are completely resilient thanks to the extensive experience I gained in the fight against the FBI. My competitors do not have this experience, and they do not have the unlimited budget that I have for developing new software. 3. After everything I have been through, I can no longer be frightened, which means that doing business with me will be stable. 4. In my affiliate program, it is now possible to attack any critical infrastructure, healthcare organization, and military bodies. There are no more restrictions.

Q:

The 'ransomware-as-a-service' model you operate attracts quite a few questionable affiliates. How do you verify the reliability of those who want to take part in your activity?

A:

On the new platform, LockBit 4.0, anyone can get access to a basic panel for a symbolic fee of $777. The affiliate will have to prove their hacking capabilities, and only after that will they receive access to an advanced management panel for managing attacks.

Q:

What is the most significant change in the new version you developed, LockBit 4.0?

A:

In the 4.0 update, I placed a major emphasis on information security and on the resilience of the encryption algorithms I use. No one else today has encryption capabilities like mine.

Q:

It was recently reported in the media that one of the key developers in your group, Rostislav Panev, was arrested by law enforcement in Israel and will likely be extradited to the United States. What is your response to this? Did the arrest affect the group's activity?

A:

I do not know this person personally. My employees do not tell me which country they live in or what their name is. The programmers on my team change all the time. When one programmer leaves or disappears, a new programmer, even stronger, takes his place. That is the nature of how things work with us. Programmers have no OPSEC.

Q:

We are in an era of advanced artificial intelligence that is integrated into many tools and processes. Do you use artificial intelligence during your activity?

A:

No.

Q:

In the past two years, it seems that organizations have been preparing for ransomware attacks more than ever before. What does this development look like from your side?

A:

We work in the classic way, as always.

Q:

Each of us, even those who follow an unconventional path, finds inspiration somewhere. Is there a book, person, or movie that shaped your worldview or influences your approach to managing the group?

A:

Yes, and that person is the Director of the FBI. When I write answers to your questions, I look at his picture. I printed his portrait and hung it on the wall. He inspires me to work. He wants to destroy me, and I want him to have work.

Q:

Anything else you would like to say to the 35,000 followers in the channel?

A:

I want to ask your followers: 'Where are you? And why have you not joined my channel here yet?' Also, if you want a Lamborghini, Ferrari, or other worthwhile things, start your journey to a million within 5 minutes on our new platform: <redacted>

All rights reserved to the Telegram channel 讞讚砖讜转 住讬讬讘专. Content displayed is an exact transcription of the original interviews without modification.

base44
Edit with Base44