Largest international police operation against botnets takes down ransomware networks

Police coordinated by the European Union’s justice and police agencies have taken down computer networks responsible for spreading ransomware via infected emails, in what they called the biggest ever international operation against the lucrative form of cybercrime.

The European Union’s judicial cooperation agency, Eurojust, said Thursday that police arrested four “high value” suspects, took down more than 100 servers and seized control of over 2,000 internet domains.

The huge takedown this week, codenamed Endgame, involved coordinated action in Germany, the Netherlands, France, Denmark, Ukraine, the United States and United Kingdom, Eurojust said. Also, three suspects were arrested in Ukraine and one in Armenia. Searches were carried out in Ukraine, Portugal, the Netherlands and Armenia, EU police agency Europol added.

It is the latest international operation aimed at disrupting malware and ransomware operations. It followed a massive takedown in 2021 of a botnet called Emotet, Eurojust said. A botnet is a network of hijacked computers typically used for malicious activity.

Europol pledged it would not be the last takedown.

“Operation Endgame does not end today. New actions will be announced on the website Operation Endgame,” Europol said in a statement.

Dutch police said that the financial damage inflicted by the network on governments, companies and individual users is estimated to run to hundreds of millions of euros (dollars).

“Millions of people are also victims because their systems were infected, making them part of these botnets,” the Dutch statement said.

Eurojust said that one of the main suspects earned cryptocurrency worth at least 69 million euros ($74 million) by renting out criminal infrastructure for spreading ransomware.

“The suspect’s transactions are constantly being monitored and legal permission to seize these assets upon future actions has already been obtained,” EU police agency Europol added.

The operation targeted malware “droppers” called IcedID, Pikabot, Smokeloader, Bumblebee and Trickbot. A dropper is malicious software usually spread in emails containing infected links or attachments such as shipping invoices or order forms.

“This approach had a global impact on the dropper ecosystem,” Europol said. “The malware, whose infrastructure was taken down during the action days, facilitated attacks with ransomware and other malicious software.”

Dutch police cautioned that the actions should alert cybercriminals that they can be caught.

“This operation shows that you always leave tracks, nobody is unfindable, even online,” Stan Duijf, of the Dutch National Police, said in a video statement.
The deputy head of Germany’s Federal Criminal Police Office, Martina Link, described it as “the biggest international cyber police operation so far.”

“Thanks to intensive international cooperation, it was possible to render six of the biggest malware families harmless,” she said in a statement.

German authorities are seeking the arrest of seven people on suspicion of being members of a criminal organization whose aim was to spread the Trickbot malware. An eighth person is suspected of being one of the ringleaders of the group behind Smokeloader.

Europol said it was adding the eight suspects being sought by Germany to its most-wanted list.

—Mike Corder, Associated Press

Geir Moulson, Associated Press writer, contributed to this report.

https://www.fastcompany.com/91133244/international-police-operation-takes-down-ransomware-networks?partner=rss&utm_source=rss&utm_medium=feed&utm_campaign=rss+fastcompany&utm_content=rss

Creată 11mo | 30 mai 2024, 19:30:05


Autentifică-te pentru a adăuga comentarii

Alte posturi din acest grup

Inside the Grindr CEO’s ‘hardcore’ vision for the LGBTQ dating app’s future

George Arison is telling me about a hookup.

Arison, the 47-year-old CEO of the LGBTQ dating app and social network Grindr, recalls an encounter with a man who ranked low in physical chem

6 mai 2025, 11:10:04 | Fast company - tech
‘AI is already eating its own’: Prompt engineering is quickly going extinct

Just two years ago, prompt engineering was hailed as a hot new job in tech. Now, it has all but disappeared.

At the beginning of the corporate AI boom, some companies sought out large la

6 mai 2025, 11:10:04 | Fast company - tech
Goodbye human drivers? Waymo’s robotaxis are now fully operational

Summoning a robotaxi from your phone is not a futuristic fantasy since Waymo achieved full commercial deployment.

https://www.fastcompany.com/91325288/goodbye-human-drivers-waymos-robotaxis-a

6 mai 2025, 08:50:02 | Fast company - tech
‘You got to be really careful what you tie your name to’: The Hawk Tuah girl is planning a rebrand

Haliey Welch, better known as the Hawk Tuah girl, is ready for a rebrand.

After being thrust into the spotlight in 2024, thanks to her now-iconic “Hawk Tuah” catchphrase—featured in a vi

5 mai 2025, 23:30:07 | Fast company - tech
Anthropic hires a top Biden official to lead its new AI-for-social-good team (exclusive)

Anthropic is turning to a Biden administration alum to run its new Beneficial Deployments team, which is tasked with helping extend the benefits of its AI to organizations focused on social good—p

5 mai 2025, 21:20:03 | Fast company - tech
Speed-limiting devices could be coming for reckless U.S. drivers in these states

A teenager who admitted being “addicted to speed” behind the wheel had totaled two other cars in the year before he slammed into a minivan at 112 mph (180 kph) in a Seattle suburb,

5 mai 2025, 16:40:03 | Fast company - tech
Nvidia chips could face new tracking rules under a bipartisan bill to stop chip smuggling to China

A U.S. lawmaker plans to introduce legislation in coming weeks to verify the location of

5 mai 2025, 16:40:02 | Fast company - tech