{"id":28915,"date":"2024-12-24T12:46:40","date_gmt":"2024-12-24T12:46:40","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=28915"},"modified":"2024-12-24T14:59:28","modified_gmt":"2024-12-24T14:59:28","slug":"lockbit-developer-arrested-in-israel","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/lockbit-developer-arrested-in-israel\/","title":{"rendered":"LockBit Ransomware Developer Arrested and Extradicted in Israel"},"content":{"rendered":"<p>US authorities have detained <strong>a developer associated with the LockBit group<\/strong>, one of the most active ransomware creators. Investigators allege he has been working as a programmer for the notorious hacker group since January 2022. Israeli law enforcement took him into custody, and the U.S. is now seeking his extradition.<\/p>\n<h2>LockBit Developer Rostislav Panev Charged<\/h2>\n<p><a href=\"https:\/\/www.justice.gov\/opa\/pr\/united-states-charges-dual-russian-and-israeli-national-developer-lockbit-ransomware-group\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">In February 2024<\/a>, UK and US law enforcement <a href=\"https:\/\/gridinsoft.com\/blogs\/lockbit-ransomware-taken-down\/\">seized the infrastructure<\/a>, including its servers and websites. Thousands of decryption keys and victim-related information were obtained by the authorities. Affected companies are now being encouraged to seek assistance in recovering their stolen information.<\/p>\n<p>Rostislav Panev,  51-y.o. dual Russian-Israeli citizen, has been charged in the U.S. for his alleged role as <strong>a developer of LockBit, specifically the cryptor and data extraction tools, and also maintained the gang&#8217;s infrastructure. His brainchild is what enabled cybercriminals to <a href=\"https:\/\/gridinsoft.com\/ransomware\">deploy ransomware<\/a> without advanced technical skills by offering pre-built tools and infrastructure.<\/p>\n<figure id=\"attachment_28918\" aria-describedby=\"caption-attachment-28918\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Rostislav-Panev-social-media.webp\" alt=\"Rostislav Panev social media screenshot\" width=\"1030\" height=\"962\" class=\"size-full wp-image-28918\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Rostislav-Panev-social-media.webp 1030w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Rostislav-Panev-social-media-300x280.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Rostislav-Panev-social-media-1024x956.webp 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Rostislav-Panev-social-media-768x717.webp 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/Rostislav-Panev-social-media-860x803.webp 860w\" sizes=\"auto, (max-width: 1030px) 100vw, 1030px\" \/><figcaption id=\"caption-attachment-28918\" class=\"wp-caption-text\">Rostislav Panev social media<\/figcaption><\/figure>\n<p>Panev, who was active in the operation from 2019 to February 2024, was arrested in Israel in August 2024 and is currently awaiting extradition to the U.S. This is a rather unusual situation as Israel typically refuses to proceed with extradition of their citizens. Yet it seems this time the guy is way too bad for Bagatz to cover him.<\/p>\n<h2>What is LockBit Ransomware?<\/h2>\n<p>LockBit is a ransomware-as-a-service (RaaS) platform that allows cybercriminals to deploy ransomware without requiring advanced technical skills. It provides pre-built tools and infrastructure, enabling attackers to encrypt data and demand ransoms. It has several versions and we have a separate post <a href=\"https:\/\/gridinsoft.com\/ransomware\/lockbit\">dedicated to LockBit ransomware<\/a>.<\/p>\n<figure id=\"attachment_28934\" aria-describedby=\"caption-attachment-28934\" style=\"width: 1435px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/lockbit-leak-site.png\" alt=\"LockBit Darknet site screenshot\" width=\"1435\" height=\"630\" class=\"size-full wp-image-28934\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/lockbit-leak-site.png 1435w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/lockbit-leak-site-300x132.png 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/lockbit-leak-site-1024x450.png 1024w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/lockbit-leak-site-768x337.png 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/lockbit-leak-site-860x378.png 860w\" sizes=\"auto, (max-width: 1435px) 100vw, 1435px\" \/><figcaption id=\"caption-attachment-28934\" class=\"wp-caption-text\">Darknet site of the ransomware gang<\/figcaption><\/figure>\n<p>Although the suspect&#8217;s lawyer, Sharon Nahari, is prepared to vigorously defend his client and claims he was merely a developer communicating with the group via Telegram, an analysis of cryptocurrency proceeds suggests otherwise. Panev is alleged to have earned <strong>$230,000<\/strong> between June 2022 and February 2024 through cryptocurrency payments tied to his work with LockBit.<\/p>\n<p>Evidence recovered from his computer indicates that he had access to source code and tools, including StealBit. StealBit is a data exfiltration tool used to steal sensitive information before encrypting victims&#8217; systems. His involvement went beyond coding; he also provided technical guidance and worked closely with <a href=\"https:\/\/gridinsoft.com\/blogs\/lockbit-leader-identity-revealed\/\">Dmitry Khoroshev, known as LockBitSupp<\/a>.<\/p>\n<figure id=\"attachment_28920\" aria-describedby=\"caption-attachment-28920\" style=\"width: 500px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev.webp\" alt=\"Khoroshev image\" width=\"1920\" height=\"2400\" class=\"size-full wp-image-28920\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev.webp 1920w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev-240x300.webp 240w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev-819x1024.webp 819w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev-768x960.webp 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev-1229x1536.webp 1229w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev-1638x2048.webp 1638w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev-860x1075.webp 860w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/khoroshev-1536x1920.webp 1536w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\" \/><figcaption id=\"caption-attachment-28920\" class=\"wp-caption-text\">Lockbit Ransomware Administrator Dmitry Yuryevich Khoroshev<\/figcaption><\/figure>\n<p>How about victims, the LockBit attacked <strong>over 2,500 entities across 120 countries<\/strong>, targeting victims ranging from small businesses to critical infrastructure. The group reportedly generated $500 million in illicit profits. Despite a major law enforcement operation, &#8216;Cronos,&#8217; which dismantled its infrastructure in February 2024, the group has announced plans for a resurgence with LockBit 4.0, expected in February 2025.<\/p>\n<h2>LockBit 4.0 Released<\/h2>\n<p>Despite losing their key developer, the ransomware group managed <strong>to release a new version of their ransomware<\/strong>. They\u2019ve announced the release on their Darknet leak pages, and also launched a whole new affiliate hiring campaign. It is not new for the gang to perform such actions in a pompous manner, yet it looks strange considering all the previous events.<\/p>\n<div class=\"box\">We have a dedicated article regarding <a href=\"https:\/\/gridinsoft.com\/blogs\/lockbit-4-0-released-new-infrastructure\/\">LockBit 4.0 ransomware release<\/a>, with the detailed description of what the analysts have found in the new variant of odious malware.<\/div>\n","protected":false},"excerpt":{"rendered":"<p>US authorities have detained a developer associated with the LockBit group, one of the most active ransomware creators. Investigators allege he has been working as a programmer for the notorious hacker group since January 2022. Israeli law enforcement took him into custody, and the U.S. is now seeking his extradition. LockBit Developer Rostislav Panev Charged [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":28927,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[15],"tags":[619,649,55],"class_list":{"0":"post-28915","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-news","8":"tag-cybersecurity","9":"tag-lockbit","10":"tag-ransomware"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2024\/12\/LockBit-Ransomware-Developer-Arrested-and-Extradicted-in-Israel.webp","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/28915","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=28915"}],"version-history":[{"count":10,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/28915\/revisions"}],"predecessor-version":[{"id":28956,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/28915\/revisions\/28956"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/28927"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=28915"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=28915"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=28915"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}