Police Dismantle Major Ukrainian Ransomware Operation

Police Dismantle Major Ukrainian Ransomware Operation

November 28, 2023 at 10:54AM

Law enforcement agencies from seven countries partnered with Europol and Eurojust to dismantle a major ransomware operation based in Ukraine. A raid resulted in the arrest of a 32-year-old ringleader and four accomplices, with more arrests made earlier this year. The cybercriminals targeted organizations worldwide, disrupting operations and causing losses of hundreds of millions of dollars. They used various ransomware families and hacking techniques to gain access to networks.

Key takeaways from the meeting notes:

1. Law enforcement agencies from seven countries collaborated with Europol and Eurojust to dismantle a significant ransomware operation based in Ukraine.
2. During the operation, 30 properties were searched, resulting in the arrest of a 32-year-old individual believed to be the ringleader, along with four accomplices.
3. The recent arrests are part of a broader operation that led to the apprehension of twelve individuals in 2021.
4. The ransomware operation targeted numerous entities across 71 countries, employing ransomware families such as MegaCortex, Hive, LockerGoga, and Dharma.
5. Suspects were involved in various activities, including hacking into the networks of targeted organizations and laundering ransom payments.
6. The suspects appeared to be affiliates of a ransomware-as-a-service model, using multiple file-encrypting ransomware families for their operations.
7. The cybercriminals used SQL injections, phishing emails, and brute force attacks to gain access to networks. They also utilized malware like TrickBot and tools such as Cobalt Strike and PowerShell Empire.
8. Over 250 servers belonging to major organizations were encrypted during the attacks, resulting in significant financial losses amounting to hundreds of millions of dollars.
9. The meeting notes provide related news articles on the arrest of two ransomware operators in Ukraine, as well as the arrest of a Russian national in Canada over LockBit ransomware attacks. Furthermore, a ransomware group that targeted over 50 companies was also dismantled in Ukraine.

Let me know if there is anything else you need assistance with.

Full Article