Behind Enemy Lines: Going undercover to breach LockBit Ransomware Op
Jon DiMaggio
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In a groundbreaking talk at DEF CON 32, cybersecurity expert Jon DiMaggio of Analyst One unveiled an unprecedented methodology for infiltrating one of the world's most prolific ransomware operations: LockBit. Shifting away from traditional technical analysis, DiMaggio detailed his two-year undercover operation, which involved deep social engineering, meticulous adversary profiling, and the cultivation of sock puppet personas to gain the trust of LockBit's core operators and affiliates. This talk, a culmination of his popular "Ransomware Diary" series, offers a rare glimpse into the human dynamics, internal workings, and recruitment strategies of a sophisticated cybercriminal enterprise.

Key moments
- 0:00 Introduction to the "love story" of breaching Lockbit
- 1:50 Developing believable sock puppets to engage Lockbit
- 2:20 Finding Lockbit's online recruitment and social forums
- 2:50 Stalking Lockbit's partners and high-value affiliates
- 3:40 Profiling Lockbit's personality through non-attack conversations
- 6:05 Revealing identified Lockbit affiliate, Matt V (Wazawaka)
Behind Enemy Lines: Going undercover to breach LockBit Ransomware Op
Speakers: Jon DiMaggio
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=dLOUzF6_Y54
Overview
In a groundbreaking talk at DEF CON 32, cybersecurity expert Jon DiMaggio of Analyst One unveiled an unprecedented methodology for infiltrating one of the world's most prolific ransomware operations: LockBit. Shifting away from traditional technical analysis, DiMaggio detailed his two-year undercover operation, which involved deep social engineering, meticulous adversary profiling, and the cultivation of sock puppet personas to gain the trust of LockBit's core operators and affiliates. This talk, a culmination of his popular "Ransomware Diary" series, offers a rare glimpse into the human dynamics, internal workings, and recruitment strategies of a sophisticated cybercriminal enterprise.
DiMaggio's presentation transcended a typical security brief, weaving a narrative that he likened to a "love story, a story of friendship, betrayal, and deceit," drawing parallels to reality dating shows. This unique storytelling approach underscored the deeply personal and psychologically complex nature of his infiltration. The significance of this work lies not just in the intelligence gathered on LockBit, but in demonstrating an innovative, human-centric approach to threat intelligence that provides unparalleled insights into the minds and motivations of adversaries, offering a new paradigm for understanding and combating ransomware groups.
The talk highlights that while the technical attack details are often the focus of security research, understanding the personalities, relationships, and operational culture of threat actors is equally, if not more, crucial for effective defense. DiMaggio’s success in penetrating LockBit’s inner circle offers invaluable lessons for law enforcement, intelligence agencies, and cybersecurity professionals seeking to disrupt and dismantle these pervasive criminal networks from the inside out.
Background
▶ Watch: Introduction to the "love story" of breaching Lockbit (0:00)
The landscape of cybercrime has been dramatically reshaped by the rise of Ransomware-as-a-Service (RaaS) models, with groups like LockBit emerging as dominant forces. These operations function much like legitimate businesses, complete with developers, marketers, and a network of affiliates responsible for initial compromise and deployment of the ransomware. LockBit, in particular, ascended to prominence by offering a robust and highly effective ransomware payload, coupled with aggressive data exfiltration and double extortion tactics. Their operations are characterized by a high degree of organization, a constant drive for recruitment, and active engagement within underground forums.
Traditional methods of combating these groups often rely on technical indicators of compromise (IOCs), malware analysis, and infrastructure takedowns. However, the transient nature of their infrastructure, combined with their adeptness at operational security (OpSec), frequently renders these approaches insufficient for long-term disruption. The human element, the individuals behind the keyboards, remains a critical blind spot for many defensive strategies. Understanding who these actors are, how they operate, and why they commit these crimes requires moving beyond technical artifacts to engage directly with their social and psychological profiles.
DiMaggio recognized that to truly understand and counter LockBit, he needed to bypass their technical defenses and penetrate their social fabric. At the time of his initial engagement two years prior to the talk, LockBit was rapidly gaining traction, though not yet the undisputed number one ransomware group. This period presented a unique opportunity to observe its growth and internal dynamics. The challenge lay in establishing credibility within a highly suspicious and insular criminal community, a task that demanded a sophisticated blend of Open-Source Intelligence (OSINT) for initial reconnaissance and Human Intelligence (HUMINT) for deep infiltration, all while maintaining a convincing cover. This talk, therefore, represents a significant departure from conventional cybersecurity research, advocating for a deeper, more personal understanding of the adversary.
Key Findings
▶ Watch: Finding Lockbit's online recruitment and social forums (2:20)
The core findings of DiMaggio's two-year undercover operation are not technical vulnerabilities in LockBit's code, but rather profound insights into the human and organizational architecture of the ransomware group. His primary discovery was the extent to which LockBit, and its affiliates, are driven by identifiable personalities, social interactions, and specific motivations that can be leveraged for intelligence.
Key findings include:
- Deep Adversary Profiling: DiMaggio successfully built comprehensive psychological profiles of LockBit's leader (referred to as "Lockbit" or "the man behind Lockbit") and key affiliates. This involved analyzing their online interactions, identifying their "favorite spots" (recruitment forums, social channels), and meticulously cataloging their conversations—not just about attacks, but about personal interests, politics, and daily life. This allowed DiMaggio to understand their "personality," "the things that make them tick," and their individual quirks, which proved invaluable for establishing rapport.
- Mapping the Affiliate Network: Through extensive observation, DiMaggio identified LockBit's critical affiliates and business partners. He tracked who LockBit interacted with most frequently and identified affiliates who maintained relationships with multiple ransomware groups, indicating their high value and potential influence within the broader cybercriminal ecosystem. This mapping revealed the intricate web of trust and transaction that underpins RaaS operations.
- Identification of Key Individuals: A significant finding was the identification and profiling of specific high-value targets, such as the affiliate known as Matt V, also referred to as Boris and widely recognized as Wazawaka. DiMaggio's ability to show personal details like Matt V's wedding photo and his custom laptop adorned with names of researchers and criminals (including DiMaggio's own) served as concrete proof of his deep access and established trust within the criminal circles. This personal connection underscores the success of the infiltration.
- Understanding Recruitment and Social Dynamics: The operation provided firsthand insight into LockBit's recruitment tactics and the social dynamics within their operational sphere. By "hanging out at his spots," DiMaggio observed how LockBit attracted new talent and maintained relationships with existing partners. He characterized LockBit as an "extreme extrovert" in these forums, indicating a reliance on personal engagement for network growth.
- The Human Element as a Vulnerability: Ultimately, the key finding is that the human element, often overlooked in technical threat intelligence, represents a significant avenue for intelligence gathering and potential disruption. By understanding the personal and social vulnerabilities of these actors, it becomes possible to predict their behaviors, anticipate their moves, and potentially sow discord or exploit internal conflicts.
These findings collectively offer a unique, inside-out perspective on a notorious ransomware group, demonstrating that effective counter-cybercrime strategies must integrate sophisticated human intelligence methodologies alongside traditional technical analyses.
Technical Deep Dive
▶ Watch: Stalking Lockbit's partners and high-value affiliates (2:50)
While the talk did not delve into the specific technical mechanics of LockBit's ransomware or exploit chains (as these were covered in his "Ransomware Diaries"), the "technical deep dive" aspect of DiMaggio's presentation lies in the sophisticated methodology of intelligence gathering and social engineering employed to infiltrate the group. This involved a multi-faceted approach blending OSINT, persona development, and sustained digital interaction.
The foundational technical aspect was the creation and maintenance of sock puppets—believable, fabricated online identities. This wasn't merely about creating a fake profile; it involved:
- Persona Development: Each sock puppet required a detailed backstory, consistent online behavior, and a credible history of interactions within the criminal underground. This included developing specific communication styles, technical jargon, and even "personal" opinions that resonated with the target audience. The goal was to make these personas indistinguishable from genuine cybercriminals, capable of passing the scrutiny of other actors in the ecosystem.
- Social Proof: The believability of a sock puppet wasn't solely dependent on its internal consistency but also on its acceptance by others. DiMaggio emphasized that these puppets "could only be used if they were believable and if other people around him believed it." This necessitated strategic interactions with peripheral actors, building a reputation and establishing a network of contacts that would lend credibility to the puppet in the eyes of LockBit and his inner circle. This process leverages the principles of social validation within online communities.
Once the personas were established, the next technical phase involved adversary reconnaissance and profiling, utilizing advanced OSINT techniques:
- Identifying "Spots" and Accounts: DiMaggio began by identifying LockBit's preferred online haunts—the dark web forums, encrypted chat channels (e.g., Telegram, Jabber), and other platforms where he would "recruit," "socialize," and "talk with other criminals and hackers." He noted that LockBit consistently used variations of "Lockbit" as his handles, simplifying initial identification. This mapping of digital territories was crucial for understanding the operational ecosystem.
- Stalking Business Partners and Affiliates: This was a critical step in building the target's social graph. DiMaggio meticulously observed LockBit's interactions, focusing on:
- Attack Resource Procurement: Identifying who LockBit was buying initial access brokers (IABs), exploit kits, malware-as-a-service (MaaS), botnet access, or other illicit services from. This provided insights into the technical capabilities and preferred attack vectors of the group.
- Affiliate Communications: Analyzing conversations with various affiliates revealed their operational methodologies, preferred targets, negotiation tactics, and even internal grievances. This helped identify "high-value targets" within the affiliate network—those who were most active or connected to multiple RaaS groups. The detailed tracking of individuals like Matt V (Wazawaka) exemplifies this depth of observation.
- Personality Profiling through Non-Attack Conversations: A key technical insight was to focus not just on attack-related discussions, but on extraneous conversations. DiMaggio "read everything they ever wrote," looking for discussions about music, politics, religion, or personal opinions. This non-technical data provided the raw material for building a deep psychological profile, understanding their motivations, biases, and potential vulnerabilities—essential for tailoring the sock puppet's interactions and building genuine rapport. This effectively turns social interactions into actionable intelligence.
The overall technical strategy was an iterative process of observation, profiling, persona development, and engagement, all conducted within the technically challenging environment of the dark web and encrypted communications. It required a deep understanding of digital footprints, social engineering principles, and the operational security practices of advanced threat actors, essentially turning the human element into a target for technical exploitation through social means.
Demo / Proof of Concept
▶ Watch: Profiling Lockbit's personality through non-attack conversations (3:40)
While Jon DiMaggio's talk at DEF CON 32 did not feature a live technical demonstration of code or exploit, the entire presentation served as a compelling proof of concept for his unconventional methodology of deep infiltration and human intelligence gathering. The "demo" was the revelation of the intelligence itself and the tangible evidence of his successful penetration into LockBit's inner circle.
DiMaggio presented several key pieces of information as evidence of his success:
- Detailed Adversary Profiles: The ability to articulate the personality traits, social habits, and online "spots" of the LockBit leader and his affiliates demonstrated a level of access far beyond typical public-source intelligence. He described LockBit as an "extreme extrovert" in online forums, a detail only observable through sustained interaction and observation.
- Identification of Key Affiliates: The most striking piece of evidence was the specific identification and personal details provided for the affiliate known as Matt V, also referred to as Boris and Wazawaka. DiMaggio showed a photograph of Matt V getting married and even a picture of one of his laptops used for criminal activities, emblazoned with names including his own. This level of personal detail, including the knowledge of his alias progression, unequivocally proved DiMaggio's close proximity and trust established with a critical member of the LockBit operation.
- Narrative of Friendship and Betrayal: The speaker's ability to frame his relationship with these criminals as a "story of friendship, love, betrayal, and deceit" underscored the depth of his engagement. This emotional connection, however manufactured on his part, was a direct result of his successful social engineering and persona development, serving as a powerful testament to the effectiveness of his undercover work.
- The "Ransomware Diaries" as Output: DiMaggio explicitly stated that "the output of what I'm going to talk to you about today is there" in his "Ransomware Diaries" series. This ongoing public-facing research, informed by his undercover work, serves as the ultimate demonstration of the actionable intelligence derived from this infiltration, detailing attack elements and operational insights that would not be possible without such deep access.
In essence, the "proof of concept" was the speaker standing before the audience, revealing the secrets of an otherwise opaque criminal enterprise, demonstrating that through meticulous social engineering and long-term engagement, it is possible to "go behind enemy lines" and gain an unprecedented understanding of even the most sophisticated cybercriminal groups.
Defensive Implications
▶ Watch: Revealing identified Lockbit affiliate, Matt V (Wazawaka) (6:05)
The insights gleaned from Jon DiMaggio's infiltration of the LockBit ransomware operation carry profound defensive implications, urging a shift in focus from purely technical defenses to a more holistic, human-centric approach to cybersecurity. Understanding the adversary on a personal level can inform more proactive and effective defensive strategies.
- Enriched Threat Intelligence: Defenders should integrate Human Intelligence (HUMINT) and adversary profiling into their threat intelligence programs. This means moving beyond IOCs and TTPs to understand the who, why, and how of threat actors. By profiling the personalities, motivations, and social dynamics of ransomware groups, organizations can anticipate their next moves, predict likely targets, and understand their negotiation styles. Intelligence should include details about their recruitment methods, preferred communication channels, and even their non-attack-related interests to build a more complete picture.
- Enhanced Social Engineering Defenses: Knowledge of how cybercriminals build trust and recruit affiliates directly informs better anti-social engineering training for employees. If attackers leverage personal interactions and psychological manipulation, organizations must educate their staff not just about recognizing phishing emails, but about the broader tactics of online persuasion and influence that could be used to gain initial access or information.
- Disruption of Affiliate Networks and Supply Chains: By understanding LockBit's "business partners" and "affiliates," defenders (especially law enforcement and intelligence agencies) can target the entire RaaS ecosystem. Disrupting the supply chain for initial access brokers (IABs), exploit kits, or other illicit services that ransomware groups rely on can significantly hamper their operations. Identifying high-value affiliates who work across multiple groups provides strategic targets for disruption efforts.
- Proactive Monitoring of Criminal Forums: Organizations should consider monitoring relevant dark web forums and underground channels not just for mentions of their brand, but for broader trends in recruitment, tool sales, and discussions that reveal adversary intent and capabilities. This OSINT activity, when combined with skilled analysis, can provide early warnings and strategic insights.
- Adversary Empathy and Prediction: Developing an "adversary empathy" – understanding what makes criminals "tick" – can lead to more effective defensive postures. If defenders understand the motivations (financial, ego, political) and even the personal grievances of threat actors, they can better predict their behavior and tailor defensive measures accordingly. For example, knowing a group's preferred attack resources can guide defensive investments in specific patches, configurations, or detection capabilities.
- Focus on Insider Threat Prevention: Understanding the recruitment tactics of ransomware groups can also inform insider threat prevention programs. If criminals build trust and rapport to bring individuals into their fold, similar tactics could be used to compromise insiders within target organizations. Defenses should consider the psychological and social vulnerabilities that could lead an insider to collaborate with threat actors.
- Strategic Counter-Operations: For national security and law enforcement entities, DiMaggio's methodology offers a blueprint for active counter-intelligence operations. By creating credible personas and infiltrating criminal networks, agencies can gather intelligence, disrupt operations from within, and potentially identify and apprehend key actors, as demonstrated by the detailed profiling of individuals like Matt V.
In essence, DiMaggio’s work underscores that cybersecurity is not just a technological battle but a human one. Defenders who grasp the human element of cybercrime—the personalities, relationships, and social engineering tactics—will be better equipped to mount a resilient and adaptive defense against evolving threats like LockBit.
Key Takeaways
- Human Intelligence is Paramount: Effective defense against sophisticated ransomware groups like LockBit requires moving beyond purely technical analysis to deeply understand the human element, including the personalities, motivations, and social dynamics of threat actors.
- Infiltration Through Social Engineering: It is possible to infiltrate and gain trust within highly insular cybercriminal networks through meticulous sock puppet development, sustained online engagement, and sophisticated social engineering.
- Adversary Profiling is Key: Comprehensive adversary profiling, which includes analyzing both attack-related and personal conversations, provides invaluable insights into an attacker's psychology, operational preferences, and potential vulnerabilities.
- Mapping the Ecosystem: Understanding the full affiliate network and attack resource supply chains of RaaS operations is crucial for disrupting their overall capabilities, rather than just individual attacks.
- Unconventional Approaches Yield Unique Insights: DiMaggio's methodology demonstrates that unconventional, long-term intelligence gathering strategies can yield unprecedented access and understanding that traditional technical methods often miss.
- Defenders Must Adapt: Cybersecurity strategies must evolve to incorporate human intelligence, enhance social engineering defenses, and proactively monitor the broader criminal ecosystem to anticipate and counter emerging threats.
About the Speaker(s)
Jon DiMaggio is a renowned cybersecurity expert and the founder of Analyst One. He is widely recognized for his pioneering work in cyber espionage and threat intelligence, particularly his deep dives into ransomware operations. DiMaggio is the author of "The Art of Cyber Warfare" and is celebrated for his popular "Ransomware Diary" series, which detailed the findings of his unique undercover infiltration of the LockBit ransomware group. Described by his introducer as "one of the top cyber espionage practitioners on the planet," DiMaggio's work emphasizes the critical importance of understanding the human element behind cyber threats. He is known for his storytelling ability and his unconventional, yet highly effective, approach to intelligence gathering, preferring to engage directly with the culture of hackers and criminals to gain unparalleled insights.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This presentation by Jon DiMaggio is a groundbreaking exposé into the human element of LockBit, demonstrating an unprecedented and highly skilled infiltration of a major ransomware operation. DiMaggio's two-year undercover work, detailed adversary profiling, and sophisticated social engineering techniques provide unparalleled, actionable intelligence. It's a critical shift from purely technical analysis to understanding the adversary's social fabric, offering a new, vital paradigm for threat intelligence and defensive strategy.
Heather Calloway (CISO) — MUST SEE
Jon DiMaggio's deep dive into LockBit's human and organizational architecture is a critical listen for any security leader. This isn't just another ransomware brief; it's a strategic intelligence exposé that fundamentally shifts how we should perceive and counter sophisticated criminal enterprises. By demonstrating the power of human intelligence and adversary profiling, DiMaggio provides a blueprint for understanding the true vulnerabilities of these groups, moving beyond technical indicators to the core of their operational fabric. This talk demands a re-evaluation of our intelligence investments and defense strategies at the highest levels.