U.S. Indicts Dmitry Khoroshev as LockBit's Developer and Administrator: $500M Extorted, 2,500 Victims in 120 Countries

The United States, United Kingdom, and Australia jointly sanctioned Russian national Dmitry Yuryevich Khoroshev — identified as LockBitSupp — as the alleged developer and administrator of LockBit ransomware, as reported by KrebsOnSecurity. A 26-count grand jury indictment from New Jersey charges Khoroshev, 31, of Voronezh, Russia, with administering LockBit from its inception in September 2019 through May 2024, during which the operation extorted at least $500 million in ransom payments, attacked more than 2,500 victims in at least 120 countries including 1,800 in the United States, and caused billions in broader losses including lost revenue, incident response, and recovery costs.

Khoroshev's Role and Revenue Share

The indictment alleges Khoroshev conceived, developed, and administered LockBit as a ransomware-as-a-service operation, typically receiving a 20 percent share of each ransom payment extorted by affiliates. Victims spanned individuals, small businesses, multinational corporations, hospitals, schools, nonprofit organizations, critical infrastructure, and government and law enforcement agencies — making LockBit, per the DOJ, the most prolific ransomware variant and group in the world during this period. The U.S. Department of State subsequently issued a $10 million bounty for information leading to Khoroshev's arrest.

Operation Cronos and the Data Deletion Lie

The indictment came approximately three months after a February 2024 joint U.S.-U.K. law enforcement operation (Operation Cronos) seized LockBit's darknet websites and repurposed them to display press releases and free decryption tools for victims. Following the raid, LockBitSupp attempted to maintain operational credibility by reassuring partners on Russian cybercrime forums, relaunching new darknet sites, and continuing extortion against prior victims including Fulton County, Georgia — threatening to publish stolen county court records unless paid before a countdown timer expired. When Fulton County refused and the timer expired, no records were published, consistent with FBI analysis that the agency had seized all of LockBit's stolen victim data. The DOJ also confirmed that LockBit never deleted victim data regardless of ransom payment, directly contradicting the group's "double extortion" promises to pay-and-delete.

Six Members Indicted: The LockBit Affiliate Network

Khoroshev is the sixth person officially indicted in connection with LockBit. Other charged members include: Russian national Artur Sungatov, who deployed LockBit against U.S. manufacturing, logistics, and insurance victims; Ivan Gennadievich Kondratyev (alias "Bassterlord"), charged with LockBit deployment against targets in the U.S., Singapore, Taiwan, and Lebanon, and additionally charged with deploying REvil/Sodinokibi to extort a California victim; Mikhail "Wazawaka" Matveev, indicted May 2023 and currently at large in Russia with a $10 million State Department reward; Mikhail Vasiliev, 35, of Bradford, Ontario, in custody in Canada awaiting U.S. extradition; and Ruslan Magomedovich Astamirov, charged June 2023 for LockBit deployments against victims in Florida, Japan, France, and Kenya, currently in U.S. custody awaiting trial.

Detection coverage

Read the full analysis on IntelFusions