How cybersecurity researcher Jon DiMaggio used fake personas to infiltrate LockBit and trick its alleged administrator into revealing operation details
Jon DiMaggio used sockpuppet accounts, then his own identity, to infiltrate LockBit and gain the trust of its alleged admin, Dmitry Khoroshev. Mastodon: @lorenzofb@infosec.exchange and @zackwhittaker@mastodon.social X: @valb00 and @lorenzofb Mastodon: @lorenzofb@infosec.exchange : NEW: This is how a security researcher was able to befriend and then dox LockBitSupp, the founder and admin of the notorious ransomware gang. — Jon DiMaggio fort was undercover, then he actually spoke to LockBitSupp as himself for a long time. … Zack Whittaker / @zackwhittaker@mastodon.social : A fascinating deep-dive interview with security researcher Jon DiMaggio of how he infiltrated the LockBit ransomware gang and figured out the identity of its ringleader — Dmitry Khoroshev — before the feds ultimately publicly outed the Russian hacker. — From @lorenzofb on the ground at Black Hat and Def Con: … X: @valb00 : Even social engineers can be socially engineered @lorenzofb : NEW: This is how a security researcher was able to befriend and then dox LockBitSupp, the founder and admin of the notorious ransomware gang. @Jon__DiMaggio says he figured out the identity of the hacker before the NCA and law enforcement revealed it. https://techcrunch.com/...
Context & Ripple Effects
LockBit’s alleged administrator had already been publicly identified and charged by UK and US authorities in the May action naming the gang’s alleged leader. DiMaggio’s account adds a researcher-led view of how the operation’s internal trust relationships could be exploited.
The episode also follows earlier reporting in which a researcher elicited ransomware operators’ business details through deception, revealing their payout and cash-out practices. It matters because the target here is the administrator behind a major ransomware brand, not merely a peripheral participant.
First-order effects
- DiMaggio obtained operational details from LockBit’s alleged administrator after building credibility through fake personas and then engaging under his real identity, weakening the group’s control over internal information.
- The reported linkage of LockBitSupp to Dmitry Khoroshev reinforces the public attribution around the gang’s founder and administrator, raising the personal exposure of its alleged leader.
Second-order effects
- Ransomware operators and their affiliates have reason to tighten vetting of prospective collaborators and contacts, which can slow recruitment and information-sharing inside criminal operations.
- Defenders and investigators can treat relationship-building and identity verification as intelligence-collection surfaces alongside technical disruption, rather than relying only on infrastructure takedowns.
Third-order effects
- If repeated, human-source infiltration can make pseudonymous ransomware-as-a-service models harder to scale: their need to recruit, negotiate and maintain reputations creates persistent exposure points.
- The broader contest may shift toward combining technical disruption, public attribution and social engineering against criminal networks; its effectiveness will depend on whether usable intelligence can be verified and operationalized.
The trend: Ransomware disruption is increasingly targeting the human trust and identity layers that enable criminal platforms to operate at scale.