This study aims to determine the mechanism and role of cryptocurrency as a means of ransom payment in lockbit ransomware attacks, to determine the effectiveness of cyber security implementation in preventing, detecting, and handling ransomware attacks that use cryptocurrency as a means of transaction, and to determine what strategies or efforts should be undertaken by relevant stakeholders (government, law enforcement, and the digital industry) in enhancing cyberlaw enforcement collaboration and strengthening cyber security to combat cryptocurrency-based ransomware attacks. This study uses a normative legal approach focuses on analyzing legal events related to relevant laws such as the Criminal Code, Law Number 11 of 2008 concerning Electronic Information and Transactions (ITE), and Law Number 27 of 2022 concerning Personal Data Protection (PDP). The novelty of this research lies in the analysis of the LockBit 2025 internal data leak, which revealed 60,000 Bitcoin addresses, enabling forensic tracking of ransomware ransoms. The research is also unique in examining the 2025 LockBit-Qilin-DragonForce alliance, which enhanced RaaS collaboration and the evolution of LockBit 5.0 post-Operation Cronos. Its implementation focuses on Indonesia's cyberlaw framework (revised 2024 ITE Law) for regulating crypto assets in the context of recent attacks on PDNS and BSI. Findings show that the LockBit-Qilin-DragonForce alliance in 2025 will increase the effectiveness of ransomware attacks through shared infrastructure and affiliates. The leak of 60,000 LockBit Bitcoin addresses reveals patterns of crypto ransom flows that can be forensically traced for cybercrime investigations. LockBit 5.0 controls 25-30% of the RaaS market again with cross-platform support (Windows/Linux/ESXi), threatening critical Indonesian infrastructure such as PDNS. The concludes that the LockBit-Qilin-DragonForce 2025 alliance increases RaaS dominance through ransomware, but the leak of 60,000 Bitcoin addresses opens up opportunities for global forensics. Indonesian cyberlaw (ITE Law 2024) requires blockchain tracing integration to block ransomware money laundering and prevent the recurrence of PDNS-BSI cases. The BSSN's hybrid cybersecurity strategy (EDR + 3-2-1 backup) effectively reduces the impact of LockBit 5.0 attacks on critical infrastructure.
Copyrights © 2026