May 15, 2024 · 4 min read
On May 7, 2024, the Office of Foreign Assets Control along with other american government agencies revealed several pieces of information about LockBit’s leader, Lockbitsupp. Let’s see what we can find out about him using this information.

Our starting point will be the OFAC specially designated nationals list. It gives us 2 email adresses linked to Lockbitsupp:
— [email protected]
— [email protected]
Thanks to Predicta Search, we can find a Github account and a Notion account linked to this email adresses

The Github account is pretty empty, but we can get the following info:
— He uses the username sitedev5
— The account has been created at 2020–11–27T11:08:01Z
— The account has been updated at 2021–03–26T15:22:38Z

The Notion account gives us a name: Дмитрий Хорошев.
Still using Predicta Search we can see that [email protected] leaked in the Yandex Food leak. It gives us a new phone number: +79521020220.

The phone number is used on Facebook.

His OPEN VK profileis also linked to the phone number!

Our friend also registered multiple sites with his email [email protected]:
— http://pra-vo.com/
— http://utepleniedoma.com/
— http://junonasonnic.online
The phone number +79521020220 is linked to his Apple account and so is the email [email protected].

Pivoting on his profile picture, we can find his old VK profil (deleted).

Yes the king image was his profile picture in 2016! He also added his real date of birth (according to the SDN list) at the latest on the 20/11/2016.

In his current VK profile we have a city: Voronezh.

Dmitry is the head of Tkaner LLC. The website http://tkaner.com who has been registered with the email [email protected].

It gives us an address:
394026, Voronezh region, o. city of Voronezh, Voronezh, Moskovsky Ave., 13/1, premises. V room 3–6.

Oh! A guy with the username sitedev5 located in Voronezh, Russia posted a review of his Mercedes-Benz GLE-Class Coupe along with some pictures.
Guess we have his license plate now : o570et and 136 is the region code for Voronezh Oblast.

Searching for his phone number in russian leaks gives us a ton of info.
— A new email address: [email protected]
— 3 phone numbers (2 new): +74732414824, +79521020220, +79673415167
For instance, the Yandex Food Leaks show he used to order food from this place in 2022:

And from here:

The phone number also allow us to find what’s probably his old VK account from when he was a teenager in 2009 (14 years old):

His selfies give us more information about his activities and his wereabouts in the past. As we can see below he served in the Russian internal troops when he was younger : he is wearing the patch for the VV MVD Internal Troops. According to Wikipedia: “Internal troops [..] are military or paramilitary, gendarmerie-like law enforcement services.”

On April 30th April 2018, Dimitry published a selfie on one of his VK account. This photo was taken in Sevastopol, approximate location: 44.601125, 33.526193.

Another selfie published on May 13th 2018 close to an high school Sevastopol.

Another selfie. No date. Taken at Chersonesus, Sevastopol.

More interestingly, we can find possible traces of Locksupp already dabbing into ransomwares in 2015. A user of the forum virusinfo.info called dkhoroshev posted about a Trojan virus, sharing the files and the price of the decryption key.

But cyberattacks may not be his only hobby as Lockbitsupp or another user of the pseudonyme sitedev5 shared on a russian blog his interest for the echinacea plant and tips on how to get rid of flies. Who said you can’t be a cyber-crime lord and a gardening enthusiast ?

During the writing of the thread at the origin of this publication, we saw many comments mocking Khoroshev’s operational security and it seems to us a little unfair. Good OPSEC is tough, it is even almost impossible for the average person. Like everyone, Khoroshev grew up with computers before cybersecurity was present in everyone’s mind and did what all teenagers did: he posted. Only then did he become the most wanted cyber criminal of his days.
Get the latest OSINT news, monthly recaps and product updates in your inbox.

August 29, 2024 · 3 min read
A second sequence of open-source discoveries leading from the hacker USDoD's Twitter profile to his real-life identity.

August 28, 2024 · 4 min read
Last week CrowdStrike revealed the identity of the famous hacker USDoD and today we will retrace how he was discovered with an open source investigation of our own.

February 22, 2024 · 3 min read
After the FBI and the NCA revealed their years-long investigation on the ransomware group Lockbit, we retrace how much information a single email address from OFAC’s sanctions list can lead to with Predicta Search.

December 1, 2021 · 4 min read
The New York Times reported that the amount of weekly flights from Middle Eastern locations to Minsk doubled from October to November 2021. Predicta Lab retraces this analysis step-by-step in order to verify the veracity of its findings.