Filter
Exclude
Time range
-
Near
He ran the world's most feared ransomware gang from the shadows. So untouchable, offered $10 million to anyone who could find him. The Law found him for free. 👇 ❇️ Dmitry Khoroshev known as LockBitSupp thrived on anonymity. He offered $10 million to anyone who could reveal his identity. LockBit claimed more than 2,000 victims worldwide. Over $500 million extracted in ransom payments and billions more in damages. Attacks hit over 100 hospitals, schools, and major corporations. Patients in hospital beds had their records locked behind ransom demands. In 2024 law enforcement didn't just chase them, but also beat them at their own game. Instead of quietly taking down LockBit's sites, investigators replaced them with law enforcement banners styled exactly like LockBit's own ransom pages. Complete with countdown timers. Poetic justice. The hunters became the hunted. Authorities released his name and a photo that went viral instantly. A young Russian with close-cropped hair. Smiling next to a pool table. Completely ordinary looking. He faces 26 criminal charges. Maximum penalty of 185 years in prison. He personally pocketed $100 million from victims. In May 2025 unknown attackers hacked what remained of his empire and left one message, "Don't do crime, CRIME IS BAD xoxo from Prague. He offered $10 million to find him. They found him for free. The most feared hacker in the world got hacked.
2
2
7
67
LockBit is back. 12 organizations hit in September 2025 alone. Half by the new LockBit 5.0 variant ("ChuongDong"). Half by LockBit Black. Targeting: 80% Windows, 20% ESXi/Linux Regions: Europe, Americas, Asia LockBitSupp evaded capture after Operation Cronos. Posted on RAMP in May: "We always rise up after being hacked." August: "Getting back to work." September: 12 victims confirmed. Affiliate model active again. $500 deposit for panel access. 30-day deadline before data leaks. Takedown disrupted infrastructure. It didn't stop the operator. Source: Check Point Research, November 2025
2
109
Dmitry Khoroshev (putinkrab) wrote the LockBit cryptolocker and sold it for $7,500, his original post is shown in the screenshot. Later, he provided support for this locker (he was part of the LockBit gang as a developer/coder). He did not have the ambition or the capability to be a leader, but he got himself deeply involved in this dirty business. At the same time, he did not receive a share of the profits and had no voice in strategic decisions. However, evidence indicates that he was connected offline with the LockBit leader, Dementiev. At the very beginning, Khoroshev also posted messages on forums under the name LockBit, but the LockBitSupp account has been used - and continues to be used - by only one person: Evgeniy Dementiev. I will provide a detailed report and additional information 👇
1
13
3,362
MISATTRIBUTION: Dmitry Khoroshev is not LockBitSupp. He appears to be a LockBit developer, not the leader. Evgeny Dementyev is LockBitSupp and the leader of LockBit. Evidence: justpaste.it/iw99v justpaste.it/lmbkf justpaste.it/mxfxz justpaste.it/il812 justpaste.it/dz1qv #Cronos @FBI @Europol
A leader of what was once the world’s most harmful cyber crime group has been unmasked and sanctioned by the UK, US and Australia, following an NCA-led international disruption campaign. #Cronos @FBI @Europol Full story ➡️ nationalcrimeagency.gov.uk/n…
22
106
25,529
LockBitSupp attribution error. This issue requires immediate attention. I encourage independent review. The wrong attribution protects the real LockBit leader and wastes law enforcement resources. I welcome scrutiny. @NCA_UK @FBI @Europol @BleepinComputer @fs0c131y @Jon__DiMaggio @ValeryMarchive @uuallan @WhichbufferArda @demonslay335 @JZBleiberg @theregister @WIRED @ComputerWeekly @bka @pancak3lullz @malwrhunterteam @LawrenceAbrams @vxunderground @RecordedFuture @GroupIB Retweets appreciated.
1
2
7
3,043
The real leader of LockBit is Evgeny Dementyev and he is the one hiding behind the nickname LockBitSupp 📌 Main idea 
In May 2024, the US, UK, and Australia officially accused Dmitry Khoroshev (born 1993, Voronezh) — he is the developer of LockBit malicious software and allegedly the main figure in the group. Khoroshev really did write code for LockBit and was part of the gang. But the public voice, administrator, and real leader under the nickname LockBitSupp is a completely different person: Evgeny Dementyev (21.07.1987, Moscow), owner of LLC “NPG”. 📌 How it all started — with the Mercedes car 
Khoroshev was found to have a black Mercedes-Benz GLE 350d (VIN WDC2923241A144235, license plate О570ЕТ136).
The car was never registered in his name personally — only to the Voronezh LLC “Epokha”, with which Khoroshev has no connection on paper.
In January 2023, he had an accident in this car — and in the database, the owner’s data was replaced: instead of Dmitry born in 1993, another Dmitry Khoroshev born in 1962 (complete falsification).
After the FBI charges on May 7, 2024, the car was quickly sold (May 22). 📌 Where did the Mercedes come from? 
Earlier (2019–2021), it was registered in Moscow to Dementyev’s LLC “NPG”, with license plates Х313ОК799.
In December 2021, the car was “transferred” through another LLC to Voronezh — to break the connection. I found traces of these manipulations in several databases.
Previously, Dementyev himself drove this same Mercedes — traffic fines from 2019–2020 exactly match his routes: Moscow–Khimki–Kyiv Highway–Kaluga Region (Lyudinovo, where his parents live). 📌 The main evidence — BMW X6 and traffic fines 
Dementyev has one of the cars: BMW X6 xDrive40i 2020 (license plate К102СХ799), registered to his same LLC “NPG”. The car is parked at his personal parking spot in Khimki (Moskovskaya St., 21). In a 2023 accident, he personally appears in the documents.
 I analyzed all 162 fines for 2023–2025.
The profile is simple:
Rare long-distance trips (1–3 times a month).
Only the Kyiv Highway, toward the Kaluga Region and back.
Not a single fine in the center of Moscow.
Most likely — a country car for a house on the Kyiv Highway. 📌 The most devastating evidence — the timeline 
I collected:
All traffic fines for the BMW (66 unique days over 3 years).
All public posts and messages from LockBitSupp (XSS forums, ReHub, Tox, Telegram) — 87 active days.
Result:
Over three years (2023–2025) — NOT A SINGLE overlap.
When fines arrive (Dementyev behind the wheel for 3–5 hours) — LockBitSupp is completely silent.
When LockBitSupp publicly posts — the car does not appear on cameras.
There are 13 striking “clusters” where fines and posts are linked — day after day they alternate:
trip → silence → series of posts → trip → silence, etc.
Examples:
December 6, 2025 — fine, then December 7–9 posts, December 10 — fine again.
August–October 2024 and 2023 — exactly the same alternations.
Statistically, the probability that two different people overlap so perfectly is negligible. This is the schedule of one person. 📌 Finale: direct contact 
On January 5, 2026, I wrote to Dementyev in Telegram anonymously:
“Evgeny Petrovich, hello. This is part of your dossier… When is it convenient to discuss?”
Dementyev read it, blocked me, deleted his avatar, and closed incoming messages.
Five days later (January 11, 2026), a new official LockBitSupp account appears in Telegram — he joins my group and announces a reward of $22,000,000 for him deanon (twice as much as the U.S. Rewards for Justice). 📌 Conclusion of the article 
Dmitry Khoroshev is an experienced malware developer (since 2011 under nicks Pin and NeroWolfe), a technical specialist, possibly an early administrator.
The real LockBitSupp — the leader of LockBit who controls everything — is Evgeny Dementyev. All sources are legal, free, and open. All details and evidence are in the article ☝️
1
1
6
1,138
💣 From Zero-Day to Day-Zero: Who was behind LockBitSupp? An independent OSINT investigation reveals a 3-year pattern of activity and vehicle use linking Evgeny Dementyev to the infamous alias. Read the full story 👉 justpaste.it/iw99v #LockBit #OSINT
4
17
61
15,304
Replying to @t43cr0wl3r
I checked with lockbitsupp, he confirmed this is fake.
4
196
RAMP Forum User Intelligence Available for Our Platform (U.S.T.A. & Catalyst) Members 🫶Our SYS initiative remains highly active, as a well-known forum member voluntarily contacted us. We are grateful for their contribution. Even when admins attempt to dox each other for 10 BTC, it's good to see some members doing it voluntarily for us. 🔍As a result, our team has acquired intelligence associated with 7,709 RAMP forum users, including the following high-value investigative datasets: 📧Private messages exchanged between threat actors, enabling reconstruction of operational planning and coordination; 👾Attachments sent and received between threat actors, supporting malware, tooling, and infrastructure attribution; 🔐Authentication and login activity, facilitating access-pattern analysis and operational security assessment; 🌌Forum search history, providing insight into intent, targeting, and operational focus; 🧐Profile information, including but not limited to registered email addresses, supporting identity correlation and cross-platform attribution; 🗣️Chat room and group communication metadata, indicating collaboration structures and coordinated activity across specific operations and campaigns. We will be correlating these datasets to support and advance multiple previously unsolved investigations. #cyberintelligence #ramp #LockBitSupp <3
4
12
75
8,773
LockBitSupp kimliğine dair çarpıcı bir de-anonimize çalışması yayınlandı. İddiaya göre, FBI'ın işaret ettiği ismin kullandığı araç aslında Evgeny Dementyev'e ait bir şirkete kayıtlı. Osint araştırmacısı, trafik cezaları ile LockBitSupp'ın online olma sürelerini eşleştirerek "yüksek güvenilirlikli" bir bağlantı kurmuş. FSB'nin koruması altındaki grubun FBI tarafından tam olarak ele geçirilemeyişi ve Detaylar ilginç. justpaste.it/lmbkf #LockBit #FBI #FSB #SiberGüvenlik

12
1,811
🚨 حساب @GangExposed_RU ينشر تحقيقًا يزعم فيه كشف هوية المشغّل الحقيقي لحساب LockBitSupp قائد مجموعة الفدية LockBit. بحسب التحقيق: 🔹 الاسم الحقيقي المزعوم: Evgeny Dementyev 🔹 تاريخ الميلاد: 21 يوليو 1987 🔹 يُعتقد أنه العقل الإداري للمجموعة (التشغيل، التفاوض، إدارة التسريبات) 🔎 ملاحظات: • ما نُشر مبني على ربطات OSINT وإسناد تقاطعي • لا يوجد حتى الآن تأكيد رسمي أو إجراء قانوني معلن.
The leader of the LockBit ransomware group is: Evgeny Dementyev (born July 21, 1987) aka LockBitSupp 👉 Details: justpaste.it/lmbkf
1
1
2
2,293
The real LockBitSupp?

ALT Ohhh Chris Pratt GIF

The leader of the LockBit ransomware group is: Evgeny Dementyev (born July 21, 1987) aka LockBitSupp 👉 Details: justpaste.it/lmbkf
2
2
30
8,364
The leader of the LockBit ransomware group is: Evgeny Dementyev (born July 21, 1987) aka LockBitSupp 👉 Details: justpaste.it/lmbkf
17
28
207
46,841
Today, the real identity of LockBitSupp will be revealed.
5
7
76
10,423
Replying to @Phish_Destroy
Yes, here is a photo of this Mercedes. And this vehicle was not just hidden — the traces related to it were also thoroughly erased (I will describe this). I like your sincerity and straightforwardness. I myself understand the categorical nature of some of my wording (I admit it). At this point, these formulations seem obvious to me, since I already know the outcome in advance. I will reveal the identity of the real LockBitSupp and point to publicly available sources of this data — anyone will be able to verify it within 10 minutes. Thank you for the objective criticism and for the outside perspective. 🤝
1
3
311
Replying to @Phish_Destroy
I wrote this article in July 2025 and decided not to publish it here until I found the real LockBitSupp. I found him, established his identity, and uncovered evidence. I will share this in the next part.
1
7
1,193
If it turns out to be true that Dmitry Khoroshev is not LockBitSupp, this will be kind of big. 👇
❗️LockBit Investigation: Dmitry Khoroshev The FBI claims he is LockBitSupp. My independent OSINT investigation shows otherwise. Dmitry Khoroshev is not LockBitSupp. 👉 justpaste.it/mxfxz
1
19
6,423
❗️LockBit Investigation: Dmitry Khoroshev The FBI claims he is LockBitSupp. My independent OSINT investigation shows otherwise. Dmitry Khoroshev is not LockBitSupp. 👉 justpaste.it/mxfxz
🔥 Is "LockBitSupp" really Dmitry Khoroshev? 🔗 Full dossier and analytical report: justpaste.it/dz1qv #LockBit #FBI #OSINT #GangExposed
6
14
113
29,776
Replying to @lockbitsupp
Интересно, смогу-ли я на днях закрыть бренд LockBit и потопить главаря группировки? (вопрос риторический)
2
2
1,388