Russian National Arrested and Charged with Conspiring to Commit LockBit Ransomware Attacks Against U.S. and Foreign Businesses

<p>FOR IMMEDIATE RELEASE<br &sol;>&NewLine; Thursday&comma; June 15&comma; 2023<br &sol;>&NewLine; Russian National Arrested and Charged with Conspiring to Commit LockBit Ransomware Attacks Against U&period;S&period; and Foreign Businesses<&sol;p>&NewLine;<div class&equals;"mh-content-ad"><script async src&equals;"https&colon;&sol;&sol;pagead2&period;googlesyndication&period;com&sol;pagead&sol;js&sol;adsbygoogle&period;js&quest;client&equals;ca-pub-9162800720558968"&NewLine; crossorigin&equals;"anonymous"><&sol;script>&NewLine;<ins class&equals;"adsbygoogle"&NewLine; style&equals;"display&colon;block&semi; text-align&colon;center&semi;"&NewLine; data-ad-layout&equals;"in-article"&NewLine; data-ad-format&equals;"fluid"&NewLine; data-ad-client&equals;"ca-pub-9162800720558968"&NewLine; data-ad-slot&equals;"1081854981"><&sol;ins>&NewLine;<script>&NewLine; &lpar;adsbygoogle &equals; window&period;adsbygoogle &vert;&vert; &lbrack;&rsqb;&rpar;&period;push&lpar;&lbrace;&rcub;&rpar;&semi;&NewLine;<&sol;script><&sol;div>&NewLine;<p>The Justice Department today announced charges against a Russian national for his involvement in deploying numerous LockBit ransomware and other cyberattacks against victim computer systems in the United States&comma; Asia&comma; Europe&comma; and Africa&period;<&sol;p>&NewLine;<p>Ruslan Magomedovich Astamirov &lpar;&Acy;&Scy;&Tcy;&Acy;&Mcy;&Icy;&Rcy;&Ocy;&Vcy;&comma; &Rcy;&ucy;&scy;&lcy;&acy;&ncy; &Mcy;&acy;&gcy;&ocy;&mcy;&iecy;&dcy;&ocy;&vcy;&icy;&chcy;&softcy;&rpar;&comma; 20&comma; of Chechen Republic&comma; will make his initial appearance later today&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;This LockBit-related arrest&comma; the second in six months&comma; underscores the Justice Department’s unwavering commitment to hold ransomware actors accountable&comma;” said Deputy Attorney General Lisa O&period; Monaco&period; &OpenCurlyDoubleQuote;In securing the arrest of a second Russian national affiliated with the LockBit ransomware&comma; the Department has once again demonstrated the long arm of the law&period; We will continue to use every tool at our disposal to disrupt cybercrime&comma; and while cybercriminals may continue to run&comma; they ultimately cannot hide&period;”<&sol;p>&NewLine;<p>According to a criminal complaint obtained in the District of New Jersey&comma; from at least as early as August 2020 to March 2023&comma; Astamirov allegedly participated in a conspiracy with other members of the LockBit ransomware campaign to commit wire fraud and to intentionally damage protected computers and make ransom demands through the use and deployment of ransomware&period; Specifically&comma; Astamirov directly executed at least five attacks against victim computer systems in the United States and abroad&period; <&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;Astamirov is the third defendant charged by this office in the LockBit global ransomware campaign&comma; and the second defendant to be apprehended&comma;” said U&period;S&period; Attorney Philip R&period; Sellinger for the District of New Jersey&period; &OpenCurlyDoubleQuote;The LockBit conspirators and any other ransomware perpetrators cannot hide behind imagined online anonymity&period; We will continue to work tirelessly with all our law enforcement partners to identify ransomware perpetrators and bring them to justice&period;”<&sol;p>&NewLine;<p>According to the criminal complaint&comma; the LockBit ransomware variant first appeared around January 2020&period; LockBit actors have executed over 1&comma;400 attacks against victims in the United States and around the world&comma; issuing over &dollar;100 million in ransom demands and receiving at least as much as tens of millions of dollars in actual ransom payments made in the form of bitcoin&period;<&sol;p>&NewLine;<p>In furtherance of his LockBit-related activities&comma; Astamirov owned&comma; controlled&comma; and used a variety of email addresses&comma; Internet Protocol &lpar;IP&rpar; addresses&comma; and other online provider accounts that allowed him and his co-conspirators to deploy LockBit ransomware and to communicate with their victims&period; Additionally&comma; in at least one circumstance&comma; law enforcement was able to trace a portion of a victim’s ransom payment to a virtual currency address in Astamirov’s control&period;<&sol;p>&NewLine;<p>&OpenCurlyDoubleQuote;The FBI is committed to pursuing ransomware actors like Astamirov&comma; who have exploited vulnerable cyber ecosystems and harmed victims&comma;” said FBI Deputy Director Paul Abbate&period; &OpenCurlyDoubleQuote;We&comma; in collaboration with our federal and international partners&comma; are fully committed to the permanent dismantlement of these types of ransomware campaigns that intentionally target people and our private sector partners&period; We will continue to leverage every resource to prevent this type of malicious&comma; criminal activity&period;”<&sol;p>&NewLine;<p>Astamirov is charged with conspiring to commit wire fraud and conspiring to intentionally damage protected computers and to transmit ransom demands&period; If convicted&comma; he faces a maximum penalty of 20 years in prison on the first charge and a maximum penalty of five years in prison on the second charge&period; Both charges are also punishable by a maximum fine of either &dollar;250&comma;000 or twice the gain or loss from the offense&comma; whichever is greatest&period;<&sol;p>&NewLine;<p>This announcement follows LockBit-related charges in two other cases from the District of New Jersey&period; In November 2022&comma; the department announced criminal charges against <a href&equals;"https&colon;&sol;&sol;www&period;justice&period;gov&sol;opa&sol;pr&sol;man-charged-participation-lockbit-global-ransomware-campaign" rel&equals;"noreferrer noopener" >Mikhail Vasiliev<&sol;a>&comma; a dual Russian and Canadian national&comma; who is currently in custody in Canada awaiting extradition to the United States&period; In May 2023&comma; the department announced the indictment of <a href&equals;"https&colon;&sol;&sol;www&period;justice&period;gov&sol;opa&sol;pr&sol;russian-national-charged-ransomware-attacks-against-critical-infrastructure" rel&equals;"noreferrer noopener" >Mikhail Pavlovich Matveev<&sol;a>&comma; aka Wazawaka&comma; aka m1x&comma; aka Boriselcin&comma; aka Uhodiransomwar&comma; for his alleged participation in separate conspiracies to deploy LockBit&comma; Babuk&comma; and Hive ransomware variants against victims in the United States and abroad&period;<&sol;p>&NewLine;<p>The FBI Newark Field Office’s Cyber Crimes Task Force is investigating the case&period; The Jersey City Police Department&comma; New Jersey State Police&comma; Newark IRS Criminal Investigation&comma; and the international partners from Europol’s European Cybercrime Centre&comma; Eurojust&comma; National Police Agency of Japan&comma; France’s Gendarmerie Nationale Cyberspace Command &lpar;Cyber Crime Investigation Unit &sol; C3N&rpar;&comma; National Crime Agency and South West Regional Organized Crime Unit of the United Kingdom&comma; Kantonspolizei Zürich of Switzerland&comma; Landeskriminalamt Schleswig-Holstein and the Bundeskriminalamt of Germany&comma; and Swedish Police Authority of Sweden also provided valuable assistance&period;<&sol;p>&NewLine;<p>Trial Attorney Jessica C&period; Peck and Jorge Gonzalez of the Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U&period;S&period; Attorneys Andrew M&period; Trombly&comma; Vinay Limbachia&comma; and David E&period; Malagold for the District of New Jersey’s Cybercrime Unit in Newark are prosecuting the case&period;<&sol;p>&NewLine;<p>The U&period;S&period; Attorney’s Office for the District of Arizona and the Justice Department’s Office of International Affairs also provided significant assistance&period;<&sol;p>&NewLine;<p>Victims of LockBit ransomware should contact their local FBI field office and visit StopRansomware&period;gov for further information&period;<&sol;p>&NewLine;<p><em>A criminal complaint is merely an allegation&period; All defendants are presumed innocent until proven guilty beyond a reasonable doubt in a court of law&period;<&sol;em><&sol;p>&NewLine;<p> Topic&lpar;s&rpar;&colon; CybercrimeComponent&lpar;s&rpar;&colon; <a href&equals;"http&colon;&sol;&sol;www&period;justice&period;gov&sol;criminal&sol;" rel&equals;"noreferrer noopener" >Criminal Division<&sol;a><a href&equals;"https&colon;&sol;&sol;www&period;justice&period;gov&sol;criminal-ccips" rel&equals;"noreferrer noopener" >Criminal &&num;8211&semi; Computer Crime and Intellectual Property Section<&sol;a><a href&equals;"https&colon;&sol;&sol;www&period;justice&period;gov&sol;criminal-oia" rel&equals;"noreferrer noopener" >Criminal &&num;8211&semi; Office of International Affairs<&sol;a><a href&equals;"http&colon;&sol;&sol;www&period;fbi&period;gov&sol;" rel&equals;"noreferrer noopener" >Federal Bureau of Investigation &lpar;FBI&rpar;<&sol;a><a href&equals;"http&colon;&sol;&sol;www&period;justice&period;gov&sol;usao-az" rel&equals;"noreferrer noopener" >USAO &&num;8211&semi; Arizona<&sol;a><a href&equals;"http&colon;&sol;&sol;www&period;justice&period;gov&sol;usao-nj" rel&equals;"noreferrer noopener" >USAO &&num;8211&semi; New Jersey<&sol;a>Press Release Number&colon; 23-666 <&sol;p>&NewLine;<p> Updated June 15&comma; 2023<a href&equals;https&colon;&sol;&sol;www&period;justice&period;gov&sol;opa&sol;pr&sol;russian-national-arrested-and-charged-conspiring-commit-lockbit-ransomware-attacks-against-us> Original Article <&sol;a><&sol;p>&NewLine;