The U.S. Department of Justice (DoJ) has announced that it has arrested and indicted a Russian national on suspicion of participating in a cyberattack using the LockBit ransomware.
Ruslan Magomedovich Astamirov, a 20-year-old from the Chechen Republic, allegedly targeted computer systems in the United States, Asia, Europe and Africa.
Astamirov is the second person to be arrested in connection with the LockBit ransomware campaign within the past six months.
This comes months after the ministry announced indictments against Mikhail Vasiliev in November 2022. Vasiliev is currently being held in Canadian custody for extradition.
Then, in May 2023, the ministry indicted Mikhail Pavlovich Matveev for deploying LockBit, Babak and Hive ransomware to victims around the world.
“The department has once again demonstrated the immense power of law in securing the arrest of a second Russian person implicated in the LockBit ransomware,” said Deputy Attorney General Lisa O Monaco.
“We will continue to use every tool at our disposal to stop cybercrime. Cybercriminals may continue to operate, but ultimately they cannot hide.”
Read more about Vasiliev arrest: Man arrested in Ontario for alleged involvement in LockBit ransomware
According to the criminal complaint, Astamilov is accused of directly carrying out at least five attacks against victims in the United States and abroad.
The Russian allegedly deployed LockBit ransomware and managed various online accounts to communicate with victims. Law enforcement reportedly found that part of the victim’s ransom was sent to a cryptocurrency address under Astamirov’s control.
The charges against him include conspiracy to commit wire fraud and conspiracy to intentionally damage a protected computer to send a ransom demand. If convicted, he could be sentenced to up to 20 years in prison for the first offense and up to five years in prison for the second offence.
“The FBI is fully committed to tracking ransomware attackers like Astamirov who have exploited a vulnerable cyber ecosystem to harm victims,” said FBI Deputy Director Paul Abeth.
“We are committed to working with our federal and international partners to permanently end these types of ransomware campaigns that intentionally target people and private sector partners.”
The LockBit ransomware gang was first detected in January 2020, leading to over 1,400 global attacks resulting in a ransom demand of over $10 million.
Most recently, this attacker claimed a breach that affected the City of Los Angeles Housing Authority (HACLA).