Trend Research published a comprehensive post-disruption analysis of Operation Cronos — the February 19, 2024 international law enforcement action that seized LockBit's darknet infrastructure, leaked its backend admin panel, exposed 193 affiliate accounts, and published LockBit-NG-Dev technical analysis on the group's own seized leak site. Trend's internal telemetry confirmed a clear drop in actual LockBit infections post-disruption, and forensic analysis of post-Cronos leak site activity revealed that over two-thirds of the 95 "new" victims posted were recycled pre-Cronos attacks — evidence that LockBitSupp was managing the site alone to maintain a facade of operational normalcy.
The Seizure: NCA Takeover and LockBit-NG-Dev Analysis
At approximately 8 p.m. GMT on February 19, 2024, LockBit's Onion sites began showing 404 errors. By 9 p.m. the sites were back online under UK National Crime Agency (NCA) control. By February 20, law enforcement repurposed the seized leak site in LockBit's own visual style — complete with LockBit's signature countdown timers — to publish NCA, FBI, and Europol press releases, indictments, decryption keys for victims, and technical findings. Authorities deliberately used the term "disruption" rather than "takedown," signaling a methodical, reputational attack on LockBit's business model rather than a purely technical seizure. Trend's analysis of LockBit-NG-Dev — an in-development .NET/CoreRT build published on the seized site — revealed a completely rewritten codebase that is platform-agnostic, has a date-based execution validity period to control affiliate use and complicate automated analysis, and lacks self-propagation and printer-based ransom note features present in earlier versions, though it retains configurable process/service termination lists and random file renaming.
Backend Leak: 193 Affiliates, Four-Level Hierarchy, and Conti Handle Overlaps
Law enforcement's release of LockBit's admin panel screenshots eliminated any ambiguity about the depth of infiltration. The leaked admin panel revealed 193 affiliate accounts (excluding the admin), a four-level hierarchy (LockBit at Level 4, affiliates at Level 1, with Level 3 suggesting direct operators or trusted senior affiliates), referral tracking via a "parent adv" dropdown for affiliate recruitment audit trails, and a victim listing page showing 1,912 victims at the time of the screenshot. Several affiliate handles overlap with known Conti group members: "Finn" (ID:5, joined one month after Conti shutdown) matching TrickBot's Buza/Maksim Rudenskiy; "Stanton" (ID:52) matching a former Conti crypter. A spike of 20 new affiliate registrations in December 2023 coincides with the ALPHV law enforcement outage — consistent with LockBitSupp's active recruiting of displaced ALPHV affiliates.
Underground Reaction: Paranoia, Forum Bans, and Arbitration Claims
Forum sentiment divided into two camps: actors who took satisfaction in LockBitSupp's disruption (amplified by LockBitSupp's pre-existing bans from Exploit.in and XSS.is) and those predicting a rebrand recovery. Within 24 hours, suspected affiliates "Desconocido" (three active campaigns disrupted) and "IT-user" (aware of Tox account seizure) inadvertently self-identified on XSS. LockBitSupp doubled the identity bounty to $20 million as a PR counter-move, attempted to add fbi.gov as the first post-Cronos leak site victim (producing no actual FBI data), and claimed compromise via a PHP vulnerability — which other forum members promptly noted was over six months old and still present on the rebuilt site. Within two weeks, multiple access brokers and initial access sellers publicly refused to work with LockBit, and arbitration claims from brokers "n30n" and "michon" surfaced over unpaid commissions, further eroding affiliate trust.
Post-Cronos Telemetry: Recycled Victims and a $2,800 Ransom
Trend's telemetry showed a measurable infection decline post-Cronos. The first confirmed post-disruption affiliate activity appeared February 27, 2024 — a low-volume South Korean campaign using ALZip archives delivered via email, with a ransom demand of just $2,800, far below LockBit's historical norms. Analysis of the 95 victims posted to the rebuilt leak site found over two-thirds were pre-Cronos attacks recycled from the old site; several were victims simultaneously claimed by ALPHV and RansomHub, suggesting LockBitSupp was repurposing other groups' data. File trees on newly posted leaked data were modified to appear recent while underlying timestamps contradicted the claimed attack dates. Operation Cronos's reputational damage — exposing affiliates, disproving data-deletion promises, and seeding distrust through implied LockBitSupp-law enforcement contact — proved more durable than a conventional infrastructure takedown would have achieved.