•
May 2023: DOJ announced an operation code-named MEDUSA which disrupted a
sophisticated global malware network called Snake. The operation disabled the malware
on compromised computers using a tool created by the FBI. Simultaneously, the FBI,
NSA, CISA, DoD Cyber National Mission Force, and international partners released a
joint CSA attributing the malware to Russia’s Federal Security Service (FSB).
•
July 2023: CISA announced the prevention of over 400 attempted ransomware
operations since the beginning of the year. CISA disrupted these operations by passing to
victims technical information paired with advice on how to best prevent further
exploitation or harm.
•
August 2023: DOJ announced a multinational operation which disrupted the Qakbot
botnet and malware and took down its infrastructure. In 2023, cybercriminals used this
infrastructure to commit ransomware, financial fraud, and other forms of criminal activity
around the world. Dismantling this botnet involved gaining comprehensive access to
compromised infrastructure and deploying a custom script to remove the malicious code
from victim computers. FBI also seized $8.6M in cryptocurrency in illicit profits. CISA
and the FBI disseminated Qakbot infrastructure IOCs through a joint CSA.
•
December 2023: DOJ announced a disruption campaign against the ALPHV/Blackcat
ransomware group, which had claimed over 1,000 victims around the world. At the time,
ALPHV/Blackcat was the world’s second-most popular ransomware-as-a-service variant,
presenting would-be cybercriminals with an easy-to-use toolset for executing extortion
ransomware attacks. The FBI developed a decryption tool that enabled field offices and
international partners to provide support to affected victims. CISA and the FBI
disseminated ALPHV/Blackcat IOCs and TTPs through a joint CSA.
•
December 2023: DOJ announced that Anatoly Legkodymov, the founder and majority
owner of Bitzlato Ltd., a cryptocurrency exchange that served as a primary conduit for
dark market purchasers and sellers, as well as a safe haven for illicit transactions by
ransomware criminals, pleaded guilty to operating a money transmitting business that
transmitted illicit funds.
•
January 2024: DOJ announced a court-authorized online operation that disrupted a
botnet that PRC state-sponsored actors used to conceal the hacking of U.S. and allied
critical infrastructure. The PRC actors used a botnet comprised of small home/small
office (SOHO) routers to obfuscate their hacking of, and enduring surreptitious access to,
U.S. critical infrastructure networks. FBI, CISA, and NSA issued several CSAs with
detailed technical information about the PRC TTPs, allowing cybersecurity professionals
to detect and prevent similar intrusions into their networks.
•
February 2024: DOJ announced a disruption campaign, in coordination with other
international law enforcement partners, of the LockBit ransomware group, which had
claimed over 2,000 victims around the world. The United Kingdom, in cooperation with
the FBI and other partners, also developed decryption capabilities for affected victims.
2024 REPORT
16
ON THE CYBERSECURITY
OF THE UNITED STATES
POSTURE