In a coordinated action, law enforcement agencies from the US, UK, France and Spain have announced a series of arrests, charges and server shutdowns against Russian cybercrime. In particular, these measures target the LockBit ransomware-as-a-service operation and the criminal group Evil Corp.
Important findings
- Coordinated action: Law enforcement agencies from several countries have taken joint action against LockBit and Evil Corp.
- Arrests and charges: Aleksandr Viktorovich Ryzhenkov, a suspected LockBit affiliate, has been charged and linked to over $100 million in extortion demands.
- Operation Cronos: This international initiative aims to disrupt LockBit’s infrastructure and fight cybercrime.
The announcements coincided with the second day of the annual meeting of the International Counter Ransomware Initiative, a U.S.-led coalition of over 60 countries committed to working together in the fight against ransomware.
The British National Crime Agency (NCA) reported that Ryzhenkov acted as the “right hand” of Maksim Yakubets, the leader of Evil Corp. This group has been in the international law enforcement focus since 2019, which has significantly limited their capabilities.
Details about the arrests
- Ryzhenkov’s role: He is accused of creating more than 60 LockBit ransomware builds and extorting at least $100 million from victims.
- Extended Sanctions: The US, Australia and UK have imposed financial sanctions on Ryzhenkov and other individuals as well as 2 Russian companies acting on behalf of Evil Corp.
The NCA noted that Ryzhenkov was involved in the development of several malware strains for Evil Corp, which are associated with attacks in over 40 countries.
LockBit under pressure
Spanish police have arrested a suspect who acted as the operator of a criminal “bulletproof” infrastructure and seized 9 servers. These measures are part of Operation Cronos, which aims to disrupt LockBit infrastructure.
French police announced that a suspected LockBit malware developer was arrested at their request while on holiday outside Russia.
Effects of the operation
The measures already seem to have an impact on LockBit’s operations. Several affiliates have reportedly left the group, leading to a decrease in attacks. The NCA noted that LockBit has been less active in recent months and some of its claimed victims may have been fabricated.
Law enforcement authorities have also revealed the identity of Dmitry Khoroshev, the alleged leader of LockBit. He is accused of extorting at least $100 million from victims.
Conclusion
International cooperation in the fight against ransomware is showing initial success. The measures taken against LockBit and Evil Corp are a significant step towards combating cybercrime and strengthening global security. Developments in this matter will continue to be closely monitored as law enforcement agencies are determined to fight cybercrime and hold those responsible accountable.
Sources
- LockBit and Evil Corp Targeted in Anti-Ransomware Crackdown, BankInfoSecurity.



