Int’l Police Operation Takes Down Ransomware Networks, Arrests 4 Suspects

FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo
FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo
TT

Int’l Police Operation Takes Down Ransomware Networks, Arrests 4 Suspects

FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo
FILE PHOTO: A man takes part in a hacking contest during the Def Con hacker convention in Las Vegas, Nevada, US on July 29, 2017. REUTERS/Steve Marcus/File Photo

Police coordinated by the European Union's justice and police agencies have taken down computer networks responsible for spreading ransomware via infected emails, in what they called the biggest ever international operation against the lucrative form of cybercrime.
The European Union's judicial cooperation agency, Eurojust, said Thursday that police arrested four “high value” suspects, took down more than 100 servers and seized control of over 2,000 internet domains.
The huge takedown this week, codenamed Endgame, involved coordinated action in Germany, the Netherlands, France, Denmark, Ukraine, the United States and United Kingdom, Eurojust said. Also, three suspects were arrested in Ukraine and one in Armenia. Searches were carried out in Ukraine, Portugal, the Netherlands and Armenia, EU police agency Europol added.
It is the latest international operation aimed at disrupting malware and ransomware operations. It followed a massive takedown in 2021 of a botnet called Emotet, Eurojust said. A botnet is a network of hijacked computers typically used for malicious activity.
Europol pledged it would not be the last takedown, The Associated Press reported.
“Operation Endgame does not end today. New actions will be announced on the website Operation Endgame," Europol said in a statement.
Dutch police said that the financial damage inflicted by the network on governments, companies and individual users is estimated to run to hundreds of millions of euros (dollars).
“Millions of people are also victims because their systems were infected, making them part of these botnets,” the Dutch statement said.
Eurojust said that one of the main suspects earned cryptocurrency worth at least 69 million euros ($74 million) by renting out criminal infrastructure for spreading ransomware.
“The suspect’s transactions are constantly being monitored and legal permission to seize these assets upon future actions has already been obtained,” EU police agency Europol added.
The operation targeted malware “droppers” called IcedID, Pikabot, Smokeloader, Bumblebee and Trickbot. A dropper is malicious software usually spread in emails containing infected links or attachments such as shipping invoices or order forms.
“This approach had a global impact on the dropper ecosystem," Europol said. “The malware, whose infrastructure was taken down during the action days, facilitated attacks with ransomware and other malicious software.”
Dutch police cautioned that the actions should alert cybercriminals that they can be caught.
“This operation shows that you always leave tracks, nobody is unfindable, even online,” Stan Duijf, of the Dutch National Police, said in a video statement.
The deputy head of Germany’s Federal Criminal Police Office, Martina Link, described it as “the biggest international cyber police operation so far.”
“Thanks to intensive international cooperation, it was possible to render six of the biggest malware families harmless,” she said in a statement.
German authorities are seeking the arrest of seven people on suspicion of being members of a criminal organization whose aim was to spread the Trickbot malware. An eighth person is suspected of being one of the ringleaders of the group behind Smokeloader.
Europol said it was adding the eight suspects being sought by Germany to its most-wanted list.



Expelled S.Africa Envoy to US Back Home 'With No Regrets'

Expelled South Africa Ambassador Ebrahim Rasool speaks to supporters following his arrival at Cape Town International Airport in Cape Town, South Africa, Sunday, March 23, 2025. (AP Photo/Nardus Engelbrecht)
Expelled South Africa Ambassador Ebrahim Rasool speaks to supporters following his arrival at Cape Town International Airport in Cape Town, South Africa, Sunday, March 23, 2025. (AP Photo/Nardus Engelbrecht)
TT

Expelled S.Africa Envoy to US Back Home 'With No Regrets'

Expelled South Africa Ambassador Ebrahim Rasool speaks to supporters following his arrival at Cape Town International Airport in Cape Town, South Africa, Sunday, March 23, 2025. (AP Photo/Nardus Engelbrecht)
Expelled South Africa Ambassador Ebrahim Rasool speaks to supporters following his arrival at Cape Town International Airport in Cape Town, South Africa, Sunday, March 23, 2025. (AP Photo/Nardus Engelbrecht)

The South African ambassador who was expelled from the United States in a row with President Donald Trump's government arrived home on Sunday to a raucous welcome and struck a defiant tone over the decision.

Ties between Washington and Pretoria have slumped since Trump cut financial aid to South Africa over what he alleges is its anti-white land policy, its genocide case against Israel at the International Court of Justice (ICJ) and other foreign policy clashes.

"It was not our choice to come home, but we come home with no regrets," expelled ambassador Ebrahim Rasool said in Cape Town after he was ousted from Washington on accusations of being "a race-baiting politician" who hates Trump.

US Secretary of State Marco Rubio said last week Rasool was expelled after he described Trump's Make America Great Again movement as a supremacist reaction to diversity in the United States.

Rasool was greeted with cheers and applause from hundreds of placard-waving supporters mostly clad in the green and yellow of the ruling African National Congress party at Cape Town International Airport, AFP reported.

"I want to say that we would have liked to come back with a welcome like this if we could report to you that we had turned away the lies of a white genocide in South Africa, but we did not succeed in America with that," he said with a megaphone after a more than 30-hour trip via Qatari capital Doha.

The former anti-apartheid campaigner defended his remarks about Trump's policies, saying he had intended to analyze a political phenomenon and warn South Africans that the "old way of doing business with the US was not going to work".

"Our language must change not only to transactionality but also a language that can penetrate a group that has clearly identified a fringe white community in South Africa as their constituency," he said.

"The fact that what I said caught the attention of the president and the secretary of state and moved them enough to declare me persona non grata says that the message went to the highest office," he added.