Int’l Police Operation Takes Down Ransomware Networks, Arrests 4 Suspects

FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo
FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo
TT

Int’l Police Operation Takes Down Ransomware Networks, Arrests 4 Suspects

FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo
FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo

Police coordinated by the European Union's justice and police agencies have taken down computer networks responsible for spreading ransomware via infected emails, in what they called the biggest ever international operation against the lucrative form of cybercrime.
The European Union's judicial cooperation agency, Eurojust, said Thursday that police arrested four “high value” suspects, took down more than 100 servers and seized control of over 2,000 internet domains.
The huge takedown this week, codenamed Endgame, involved coordinated action in Germany, the Netherlands, France, Denmark, Ukraine, the United States and United Kingdom, Eurojust said. Also, three suspects were arrested in Ukraine and one in Armenia. Searches were carried out in Ukraine, Portugal, the Netherlands and Armenia, EU police agency Europol added.
It is the latest international operation aimed at disrupting malware and ransomware operations. It followed a massive takedown in 2021 of a botnet called Emotet, Eurojust said. A botnet is a network of hijacked computers typically used for malicious activity.
Europol pledged it would not be the last takedown, The Associated Press reported.
“Operation Endgame does not end today. New actions will be announced on the website Operation Endgame," Europol said in a statement.
Dutch police said that the financial damage inflicted by the network on governments, companies and individual users is estimated to run to hundreds of millions of euros (dollars).
“Millions of people are also victims because their systems were infected, making them part of these botnets,” the Dutch statement said.
Eurojust said that one of the main suspects earned cryptocurrency worth at least 69 million euros ($74 million) by renting out criminal infrastructure for spreading ransomware.
“The suspect’s transactions are constantly being monitored and legal permission to seize these assets upon future actions has already been obtained,” EU police agency Europol added.
The operation targeted malware “droppers” called IcedID, Pikabot, Smokeloader, Bumblebee and Trickbot. A dropper is malicious software usually spread in emails containing infected links or attachments such as shipping invoices or order forms.
“This approach had a global impact on the dropper ecosystem," Europol said. “The malware, whose infrastructure was taken down during the action days, facilitated attacks with ransomware and other malicious software.”
Dutch police cautioned that the actions should alert cybercriminals that they can be caught.
“This operation shows that you always leave tracks, nobody is unfindable, even online,” Stan Duijf, of the Dutch National Police, said in a video statement.
The deputy head of Germany’s Federal Criminal Police Office, Martina Link, described it as “the biggest international cyber police operation so far.”
“Thanks to intensive international cooperation, it was possible to render six of the biggest malware families harmless,” she said in a statement.
German authorities are seeking the arrest of seven people on suspicion of being members of a criminal organization whose aim was to spread the Trickbot malware. An eighth person is suspected of being one of the ringleaders of the group behind Smokeloader.
Europol said it was adding the eight suspects being sought by Germany to its most-wanted list.



7 Killed by Russian Attacks as Moscow Pushes Ahead in Ukraine's East

Ukrainian rescuers work at the site of a missile strike on a private building in Cherkaska Lozova, Kharkiv region, northeastern Ukraine, 31 August 2024, amid the Russian invasion. EPA/SERGEY KOZLOV
Ukrainian rescuers work at the site of a missile strike on a private building in Cherkaska Lozova, Kharkiv region, northeastern Ukraine, 31 August 2024, amid the Russian invasion. EPA/SERGEY KOZLOV
TT

7 Killed by Russian Attacks as Moscow Pushes Ahead in Ukraine's East

Ukrainian rescuers work at the site of a missile strike on a private building in Cherkaska Lozova, Kharkiv region, northeastern Ukraine, 31 August 2024, amid the Russian invasion. EPA/SERGEY KOZLOV
Ukrainian rescuers work at the site of a missile strike on a private building in Cherkaska Lozova, Kharkiv region, northeastern Ukraine, 31 August 2024, amid the Russian invasion. EPA/SERGEY KOZLOV

Russian shelling in the town of Chasiv Yar on Saturday killed five people, as Moscow’s troops pushed ahead in Ukraine’s eastern Donetsk region.
The attack struck a high-rise building and a private home, said regional Gov. Vadym Filaskhin, who said the victims were men aged 24 to 38. He urged the last remaining residents to leave the front-line town, which had a pre-war population of 12,000.
“Normal life has been impossible in Chasiv Yar for more than two years,” Filaskhin wrote on social media. “Do not become a Russian target — evacuate.” A further two people were killed by Russian shelling in the Kharkiv region. One victim was pulled from the rubble of a house in the village of Cherkaska Lozova, said Gov. Oleh Syniehubov, while a second woman died of her wounds while being transported to a hospital.
Meanwhile, Russia’s Ministry of Defense said it captured the town of Pivnichne, also in Ukraine’s Donetsk region. The Associated Press could not independently verify the claim.
Russian forces have been driving deeper into the partly occupied eastern region, the total capture of which is one of the Kremlin’s primary ambitions. Russia’s army is closing in on Pokrovsk, a critical logistics hub for the Ukrainian defense in the area.
At the same time, Ukraine has sent its forces into Russia’s Kursk region in recent weeks in the largest incursion onto Russian soil since World War II. The move is partly an effort to force Russia to draw troops away from the Donetsk front.
Elsewhere, the number of wounded following a Russian attack on the Ukrainian city of Kharkiv on Friday continued to rise.
Six people were killed, including a 14-year-old girl, when glide bombs struck five locations across the city, said regional Gov. Oleh Syniehubov. Writing on social media Saturday, he said that the number of injured had risen from 47 to 96.
Syniehubov also confirmed that the 12-story apartment block that was hit by one bomb strike, setting the building ablaze and trapping at least one person on an upper floor, would be partly demolished.
Ukrainian officials have previously pointed to the Kharkiv strikes as further evidence that Western partners should scrap restrictions on what the Ukrainian military can target with donated weapons.
In an interview with CNN on Friday, Ukrainian Defense Minister Rustem Umerov said that Kyiv had presented Washington with a list of potential long-range targets within Russia for its approval. “I hope we were heard,” he said.
He also denied speculation that Ukrainian President Volodymyr Zelenskyy ’s decision to dismiss the commander of the country’s air force Friday was directly linked to the destruction of an F-16 warplane that Ukraine received from its Western partners four days earlier.
The order to dismiss Lt. Gen. Mykola Oleshchuk was published on the presidential website minutes before an address which saw Zelenskyy stress the need to “take care of all our soldiers.”
“This is two separate issues,” said Umerov. “At this stage, I would not connect them.”
The number of injured also continued to rise in the Russian border region of Belgorod, where five people were killed Friday by Ukrainian shelling, said Gov. Vyacheslav Gladkov. He said Sunday that 46 people had been injured, of whom 37 were in the hospital, including seven children. Writing on social media, Gladkov also said that two others had been injured in Ukrainian shelling across the region.