 • May 2023: DOJ announced an operation code-named MEDUSA which disrupted a sophisticated global malware network called Snake. The operation disabled the malware on compromised computers using a tool created by the FBI. Simultaneously, the FBI, NSA, CISA, DoD Cyber National Mission Force, and international partners released a joint CSA attributing the malware to Russia’s Federal Security Service (FSB). • July 2023: CISA announced the prevention of over 400 attempted ransomware operations since the beginning of the year. CISA disrupted these operations by passing to victims technical information paired with advice on how to best prevent further exploitation or harm. • August 2023: DOJ announced a multinational operation which disrupted the Qakbot botnet and malware and took down its infrastructure. In 2023, cybercriminals used this infrastructure to commit ransomware, financial fraud, and other forms of criminal activity around the world. Dismantling this botnet involved gaining comprehensive access to compromised infrastructure and deploying a custom script to remove the malicious code from victim computers. FBI also seized $8.6M in cryptocurrency in illicit profits. CISA and the FBI disseminated Qakbot infrastructure IOCs through a joint CSA. • December 2023: DOJ announced a disruption campaign against the ALPHV/Blackcat ransomware group, which had claimed over 1,000 victims around the world. At the time, ALPHV/Blackcat was the world’s second-most popular ransomware-as-a-service variant, presenting would-be cybercriminals with an easy-to-use toolset for executing extortion ransomware attacks. The FBI developed a decryption tool that enabled field offices and international partners to provide support to affected victims. CISA and the FBI disseminated ALPHV/Blackcat IOCs and TTPs through a joint CSA. • December 2023: DOJ announced that Anatoly Legkodymov, the founder and majority owner of Bitzlato Ltd., a cryptocurrency exchange that served as a primary conduit for dark market purchasers and sellers, as well as a safe haven for illicit transactions by ransomware criminals, pleaded guilty to operating a money transmitting business that transmitted illicit funds. • January 2024: DOJ announced a court-authorized online operation that disrupted a botnet that PRC state-sponsored actors used to conceal the hacking of U.S. and allied critical infrastructure. The PRC actors used a botnet comprised of small home/small office (SOHO) routers to obfuscate their hacking of, and enduring surreptitious access to, U.S. critical infrastructure networks. FBI, CISA, and NSA issued several CSAs with detailed technical information about the PRC TTPs, allowing cybersecurity professionals to detect and prevent similar intrusions into their networks. • February 2024: DOJ announced a disruption campaign, in coordination with other international law enforcement partners, of the LockBit ransomware group, which had claimed over 2,000 victims around the world. The United Kingdom, in cooperation with the FBI and other partners, also developed decryption capabilities for affected victims. 2024 REPORT 16 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3