HomeSecurityUkraine arrests members of Clop ransomware gang

Ukraine arrests members of Clop ransomware gang

Ukrainian law enforcement has arrested cybercriminals linked to the Clop ransomware gang and shut down infrastructure used in attacks targeting victims worldwide since at least 2019.

Clop ransomware

See also: Ransomware: Most companies face a second attack if they pay ransom

According to the Cyberpolice Department of the National Police of Ukraine, the ransomware group is behind total financial losses of approximately $500 million.

Based on the Ukrainian police press release, it is not yet clear whether the individuals who have been arrested are associates or key members of the ransomware operation.

The cybercriminals were arrested following an international operation conducted in collaboration with law enforcement officers from the United States and the Republic of Korea.

Ukraine arrests members of Clop ransomware gang

See also: REVIL ransomware hits nuclear weapons company Sol Oriens

In addition to the encrypting attacks, the Clop ransomware gang was linked to the recent wave of Accellion data breaches that led to a drastic increase in average ransom payments calculated for the first three months of 2021.

While victims' data is encrypted as part of regular ransomware attacks, Clop's attacks did not encrypt a single byte, but instead exfiltrated large amounts of data from high-profile companies using Accellion's legacy File Transfer Tool (FTA).

The gang used the stolen data as leverage to blackmail the compromised companies with high ransom demands.

Starting in January, BleepingComputer reported Clop attacks that target Accellion for breaches:

  • Shell, Qyysecurity, Qualys,
  • Kroger,
  • the Bank of New Zealand,
  • Singtel,
  • the Australian Securities and Investments Commission (ASIC),
  • the Washington State Auditor's Office (“SAO”),
  • as well as many universities and other organizations.

The Clop gang also claimed to have stolen 2 million credit cards from Korean retailers E-Land using point-of-sale (POS) malware before deploying ransomware on their network a year later, in November 2020.

See also: G7 to Russia: Deal with ransomware gangs in the country

Previously, Clop ransomware was behind attacks on Maastricht University, AG IT Software, ExecuPharm, and Indiabulls.

The Tor payment site and Clop data leak site are still operational, so it appears that the Clop ransomware operation has not been completely shut down at this time.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS