OAK — OnChain Attack Knowledge

Worked example · 2024-02

LockBit Operation Cronos disruption — multi-jurisdiction takedown — 2024-02-19 to 2024-02-20

Loss
the relevant on-chain quantity is not a victim-side loss but the cluster-side seized-and-sanctioned surface. Per the U.K. NCA Operation Cronos disclosure: 34 servers seized across 11 jurisdictions, control of the LockBit leak-site domain taken (substituted with NCA-branded "this site is now under the control of law enforcement" content), ~7,000 decryption keys recovered (subsequently made available to victims via the FBI / NCA), ~200 cryptocurrency accounts frozen, ~14,000 affiliate-rogue accounts closed, and the U.K. NCA's "Behind the Screens" wallet-tracing publication subsequently identified more than 2,000 BTC (~$110M at then-prevailing price) in LockBit-attributable proceeds that had not yet been spent or laundered, frozen or earmarked across the affiliate-controlled wallet set. Cumulative LockBit metrics per the DOJ Khoroshev indictment: >2,000 named victims, >$120M in extortion revenue, >120 countries.
OAK Techniques observed
OAK-T5.008 (Ransomware Extortion Payment) — the extortion-payment leg of the ransomware kill chain; OAK-T7.002 (CEX Deposit-Address Layering) — the OFAC-listed cryptocurrency addresses associated with the February 2024 LockBit-affiliate designation include deposit addresses at multiple regulated and non-KYC venues per Arkham Intelligence reporting cited in [chainalysis2024lockbit], exemplifying the canonical post-2023 LockBit-affiliate off-ramp pattern; OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side methodology used by NCA, Chainalysis, and TRM Labs to maintain LockBit-affiliate-cluster identification across encryptor-version rotations and across the post-Cronos brand-degradation period, anchored on the ten SDN-listed cryptocurrency-address identifiers as cluster-anchor points.
Attribution
confirmed at the cluster-and-named-affiliate level. Coordinated U.K. NCA / U.S. FBI / Europol "Operation Cronos" disruption announced February 20, 2024 ([nca2024operationcronos]); same-day U.S. Treasury OFAC SDN designations of Sungatov and Kondratyev with ten cryptocurrency-address SDN identifiers ([ofac2024lockbitaffiliates]). The May 7, 2024 U.S. DOJ 26-count indictment unsealed against Dmitry Yuryevich Khoroshev as the LockBit developer-and-administrator ([doj2024khoroshev]), accompanied by OFAC SDN designation of Khoroshev personally ([ofac2024khoroshev]), extends the attribution layer from the affiliate level to the principal-operator level. The cluster-attribution architecture across NCA / FBI / OFAC / DOJ / U.K. FCDO / Australia DFAT is the cleanest sanctions-and-indictment record of any single criminal operator in the on-chain economy.
OAK-Gnn
OAK-G05 LockBit. Subsequent OFAC enforcement against G05's enabling infrastructure layer ([ofac2025aeza] Aeza Group bulletproof-hosting designation) sustains the post-Cronos enforcement tempo and is documented inline in the OAK-G05 actor card.
Key teaching point
Operation Cronos is the canonical worked example of coordinated multi-jurisdiction sanctions-and-indictment disruption against a RaaS cluster on the public record. The February 2024 action and the subsequent May 2024 Khoroshev indictment together produce the cleanest multi-jurisdiction sanctions-and-indictment architecture of any single criminal operator in the on-chain economy: NCA seizure, FBI / Europol coordination, OFAC SDN designations of named affiliates and the principal operator, DOJ named-defendant indictments, U.K. FCDO and Australia DFAT designations, U.S. State Department $10M reward, and subsequent OFAC enforcement against the cluster's enabling infrastructure layer (Aeza Group, 2025).

Summary

On February 19–20, 2024, a coordinated 11-jurisdiction law-enforcement disruption operation — "Operation Cronos," led by the U.K. National Crime Agency in coordination with the U.S. FBI, Europol, and counterparts in France, Germany, Switzerland, Canada, Australia, Sweden, Finland, the Netherlands, Poland, and Japan — seized 34 servers controlling the LockBit RaaS infrastructure, took control of the LockBit leak-site domain, recovered approximately 7,000 decryption keys (subsequently made available to victims), froze approximately 200 cryptocurrency accounts, and closed approximately 14,000 affiliate-rogue accounts. The action was accompanied by same-day U.S. Treasury OFAC SDN designations of two named LockBit affiliates — Russian nationals Artur Sungatov and Ivan Kondratyev — with ten cryptocurrency-address SDN identifiers added to the SDN List as on-chain cluster-anchor points ([ofac2024lockbitaffiliates]).

The disruption produced the largest single-day OFAC-SDN-listed-cryptocurrency-address surface against a RaaS-cluster on the public record, and produced the cleanest multi-jurisdiction sanctions-and-indictment architecture of any single criminal operator in the on-chain economy. Per the U.K. NCA's subsequent "Behind the Screens" wallet-tracing publication, more than 2,000 BTC (~$110M at then-prevailing price) in LockBit-attributable proceeds had not yet been spent or laundered at the time of the action and were frozen or earmarked across the affiliate-controlled wallet set. The May 7, 2024 DOJ Khoroshev indictment ([doj2024khoroshev]) and same-day OFAC designation of Khoroshev personally ([ofac2024khoroshev]) extended the attribution layer from the affiliate level to the principal-operator level, naming Khoroshev as the LockBit developer-and-administrator and citing approximately $100M in personal Bitcoin disbursements over the operation's lifetime.

For OAK's purposes, the case is the canonical worked example of coordinated multi-jurisdiction sanctions-and-indictment disruption against a RaaS cluster and the defining counter-factual to the OAK-G10 ALPHV / BlackCat exit-scam case (examples/2024-02-change-healthcare-ransom.md). Compared with the ALPHV terminal-phase pattern (operator-side exit-scam, no OFAC SDN designations on cluster wallets, no freeze surface), the LockBit Operation Cronos pattern produced same-day OFAC SDN designations of ten cryptocurrency-address identifiers and a partial freeze surface against affiliate-controlled flows. The two cases jointly establish the attribution-with-designation-vs-attribution-without-designation contrast that defines the v0.1 OAK enforcement-architecture argument.

Timeline (UTC)

When Event OAK ref
2020-01 onward LockBit 1.0 first observed; LockBit RaaS operational continuity through versions 1.0 → 2.0 → 3.0 → Green → 4.0/NG-Dev (off-chain operating window)
2023-11-09 LockBit-affiliate intrusion of ICBCFS — see examples/2023-11-icbc-financial-services.md; financial-sector escalation factor for the subsequent designation tempo (predicate event in financial-sector escalation chain)
2024-02-19 to 2024-02-20 Operation Cronos disruption: 34 servers seized across 11 jurisdictions; LockBit leak-site domain taken under NCA control; ~7,000 decryption keys recovered; ~200 cryptocurrency accounts frozen; ~14,000 affiliate-rogue accounts closed ([nca2024operationcronos]) Multi-jurisdiction law-enforcement disruption
2024-02-20 OFAC SDN designations of Sungatov and Kondratyev with ten cryptocurrency-address SDN identifiers ([ofac2024lockbitaffiliates]); financial-sector escalation rationale cites the November 9, 2023 ICBCFS attack OFAC SDN designation at confirmed
2024-02-20 LockBit operator (LockBitSupp / Khoroshev) re-asserts limited control of leak-site infrastructure within hours; LockBit-branded extortion activity continues at much-reduced cadence (operator-side response)
2024-05-07 U.S. DOJ unsealed 26-count indictment against Dmitry Yuryevich Khoroshev as LockBit developer-and-administrator ([doj2024khoroshev]); same-day OFAC designation ([ofac2024khoroshev]); same-day coordinated U.K. FCDO and Australia DFAT designations; U.S. State Department $10M reward issued; per the indictment Khoroshev received ~$100M in personal Bitcoin disbursements over the operation's lifetime Principal-operator attribution at confirmed
2024-Q3 onward Per [chainalysis2025ransomware], LockBit-attributable ransom-payment volume in H2 2024 falls ~79% versus H1 (post-Cronos volume collapse)
2025 OFAC SDN designation of Aeza Group bulletproof-hosting provider for hosting LockBit infrastructure ([ofac2025aeza]); sustains post-Cronos enforcement tempo against G05's enabling infrastructure layer (continued enforcement tempo)

What defenders observed

  • Same-day OFAC SDN-listed cryptocurrency addresses produce a partial freeze surface. The ten OFAC-listed cryptocurrency-address identifiers associated with the February 2024 LockBit-affiliate designation include deposit addresses at multiple regulated and non-KYC venues per Arkham Intelligence reporting cited in [chainalysis2024lockbit]. The SDN listings produced a partial freeze surface: regulated-CEX deposits to the listed addresses became blocked under SDN-list compliance; further inflows from cluster-attributed wallets to regulated venues triggered counterparty-screening flags. The freeze surface was partial (not all cluster wallets are listed; downstream non-KYC venues do not honour the listing) but was meaningful — compared with the ALPHV / BlackCat case where no SDN designations on cluster wallets meant no freeze surface, the LockBit case produced a structural difference in defender / exchange / regulator capacity.
  • Counter-factual to the ALPHV exit-scam pattern. Operation Cronos is the attribution-with-designation counter-factual to the ALPHV / BlackCat exit-scam attribution-without-designation pattern. The two cases are operating-brand peers (Russian-language RaaS clusters, parallel operating windows, comparable victim-cohort sizes) but diverged in terminal-phase enforcement architecture. The contrast is the load-bearing v0.1 argument for the OAK structural claim that attribution without designation does not produce a freeze.
  • Multi-jurisdiction architecture as enforcement-tempo amplifier. The same-day NCA / FBI / Europol / OFAC / DOJ / FCDO / DFAT coordination in February 2024 — and the parallel multi-jurisdiction architecture across the May 2024 Khoroshev indictment — established that coordinated multi-jurisdiction action produces materially faster enforcement tempo than single-jurisdiction action. Defender / regulator decision-making literature should treat multi-jurisdiction coordination as a designation-tempo amplifier for RaaS-cluster disruption.
  • Decryption-key recovery as victim-side disclosure-tempo accelerant. The ~7,000 decryption keys recovered during Operation Cronos and made available to victims through the FBI / NCA materially accelerated victim-side disclosure tempo across the broader LockBit-victim cohort, because victims could decrypt without paying. Defender control-set design for ransomware response should treat law-enforcement decryptor availability as a sectoral-disclosure-tempo signal.

What this example tells contributors writing future Technique pages

  • Sanctions architecture is a first-class on-chain Technique-anchor surface. Future Group-attribution examples should treat OFAC SDN designations on cryptocurrency-address identifiers as first-class on-chain attribution-anchor surfaces, parallel to wallet-cluster-reuse signal under OAK-T8.001. The ten SDN-listed addresses associated with the February 2024 LockBit designation are the canonical worked example.
  • Multi-jurisdiction sanctions-and-indictment architecture is the highest-tempo enforcement pattern in the public record. OAK contributors writing future RaaS-cluster-attribution examples should mark multi-jurisdiction coordination explicitly when it occurs. Single-jurisdiction action is the default; multi-jurisdiction coordination is the high-tempo exception, and the Operation Cronos / Khoroshev architecture is the canonical 2024 example.
  • Decryption-key recovery is a sectoral-disclosure-tempo signal. Future ransomware-disruption examples should mark whether decryption-key recovery occurred and whether the keys were made publicly available; this materially accelerates victim-side disclosure tempo and is a structural defender / regulator signal.

Public references

  • [nca2024operationcronos] — U.K. National Crime Agency announcement of Operation Cronos and the LockBit infrastructure seizure, February 20, 2024.
  • [ofac2024lockbitaffiliates] — U.S. Treasury press release JY2114, February 20, 2024, designating Sungatov and Kondratyev with ten cryptocurrency-address SDN identifiers.
  • [doj2024khoroshev] — U.S. DOJ unsealed 26-count indictment against Dmitry Yuryevich Khoroshev, May 7, 2024.
  • [ofac2024khoroshev] — U.S. Treasury press release JY2326, May 7, 2024, designating Khoroshev as LockBit senior leader.
  • [chainalysis2024lockbit] — Chainalysis forensic write-up of the February 2024 LockBit takedown, affiliate-wallet attribution, and SDN address analysis.
  • [chainalysis2024khoroshev] — Chainalysis forensic write-up of the Khoroshev designation, Garantex / Sinbad / Bitzlato downstream flows, and aggregate LockBit-proceeds tracing.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report; documents the post-Cronos LockBit volume collapse (H2 2024 down ~79%).
  • [ofac2025aeza] — U.S. Treasury OFAC designation of Aeza Group bulletproof-hosting provider, 2025; sustains post-Cronos enforcement tempo.
  • [sophos2024lockbit] — Sophos X-Ops "LockBit after Operation Cronos" — post-disruption operational analysis.
  • [mandiant2022unc2165lockbit] — Mandiant UNC2165 LockBit affiliate profile with Evil-Corp lineage discussion (referenced from G06 documentation as well).

Discussion

Operation Cronos is the canonical worked example of coordinated multi-jurisdiction sanctions-and-indictment disruption against a RaaS cluster on the public record. The February 2024 action and the subsequent May 2024 Khoroshev indictment together produce the cleanest multi-jurisdiction sanctions-and-indictment architecture of any single criminal operator in the on-chain economy: NCA seizure, FBI / Europol coordination, OFAC SDN designations of named affiliates and the principal operator, DOJ named-defendant indictments, U.K. FCDO and Australia DFAT designations, U.S. State Department $10M reward, and subsequent OFAC enforcement against the cluster's enabling infrastructure layer (Aeza Group, 2025).

The case is also the attribution-with-designation counter-factual to the OAK-G10 ALPHV / BlackCat attribution-without-designation pattern (examples/2024-02-change-healthcare-ransom.md). The two cases are operating-brand peers, parallel operating windows, comparable victim-cohort sizes, but diverged in terminal-phase enforcement architecture: LockBit produced same-day OFAC SDN designations on ten cryptocurrency-address identifiers and a partial freeze surface; ALPHV produced no SDN designations on cluster wallets and no freeze surface despite confirmed-grade attribution at every other layer. The contrast is the load-bearing v0.1 OAK argument that attribution without designation does not produce a freeze, and that the public-policy interval between cluster-attribution and SDN-designation is itself a material exposure window during which traced proceeds can off-ramp under operator control.

Defender / regulator decision-making literature should treat the Operation Cronos architecture as the canonical 2024 enforcement-tempo template for RaaS-cluster disruption: same-day multi-jurisdiction coordination, OFAC SDN-listed cryptocurrency-address identifiers as on-chain anchor points, decryption-key recovery for victim-side disclosure-tempo acceleration, and follow-on enforcement against enabling infrastructure layers. The pattern is high-tempo and high-coordination but produces the highest-fidelity defender / regulator surface against RaaS-cluster activity in the public record.

Techniques demonstrated (3)