A joint operation conducted by Europol, the Norwegian Police and other authorities led to the arrest of 12 individuals over ransomware attacks on organizations worldwide, including critical infrastructure operators.
The suspects were involved in more than 1,800 ransomware attacks against victims across 71 countries, the threat actors focused on large corporations.
The list of victims of the group also includes Norwegian giant Norsk Hydr that was hit in 2019. In just one week after the ransomware attack, the company declared it had more than $40 million losses.
“A total of 12 individuals wreaking havoc across the world with ransomware attacks against critical infrastructure have been targeted as the result of a law enforcement and judicial operation involving eight countries.” reads the press release published by the Europol. “These attacks are believed to have affected over 1 800 victims in 71 countries. These cyber actors are known for specifically targeting large corporations, effectively bringing their business to a standstill.”
The operation took place on October 26 in Ukraine and Switzerland. Most of these suspects are suspected to have been involved in multiple high-profile cases investigated by authorities worldwide.
The police seized over USD 52 000 in cash, 5 luxury vehicles and number of electronic devices that are currently being examined by the authorities.
The suspects had different roles in prominent criminal rings, some of them were in charge penetrating the systems of the target organizations with different means, such as brute-force attacks, SQL injections, phishing emails and leveraging stolen credentials.
Once gained access to the computer network of the organizations, some of the suspects were in charge to perform lateral movement and deploying malware such as Trickbot, or post-exploitation tools such as Cobalt Strike or PowerShell Empire.
The malicious actors used several malware families in their attacks, including LockerGoga, MegaCortex and Dharma.
Some of the individuals interrogated by the police are suspected of overseeing money laundering activities, they used mixing services before cashing out the payments received by the victims.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Europol)
[adrotate banner=”5″]
[adrotate banner=”13″]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
This website uses cookies.