A Russian alleged developer of the notorious TrickBot malware gang has been arrested in South Korea after attempting to flee the country.
The TrickBot cybercrime group is responsible for a series of sophisticated malware that targets Windows and Linux devices to gain access to victims' networks, steal data, and deploy other malware, such as ransomware.

See also: Trickbot updates VNC module for high-value targets
Seoul's KBS first reported that a Russian man was stranded in South Korea due to COVID-19 restrictions and his passport subsequently expired.
After waiting over a year for his passport to be renewed, the individual attempted to depart South Korea again, but was arrested at the airport due to an extradition request from the US.
The man was allegedly working as a web browser developer for the TrickBot operation while living in Russia in 2016.
However, the Russian claims he did not know he worked for the cybercrime team after being recruited from a job advertisement.
See also: The group behind Trickbot is linked to the Diavol ransomware
The Russian's lawyer is currently fighting the US extradition effort, arguing that the US will unjustly prosecute the individual.
The TrickBot gang is responsible for several malware programs, including TrickBot, BazaLoader, BazaBackdoor, PowerTrick, and Anchor. All of these (malicious tools) are used to gain access to corporate networks, steal files and network credentials, and ultimately deploy ransomware on the network.
Both the Ryuk and Conti ransomware operations are believed to be operated by the TrickBot gang and are known to be deployed through malware .
Due to the enormous damage and financial loss this gang caused to US, the US government partnered with Microsoft and numerous security companies in an effort to take down the gang's infrastructure in October 2020.
See also: US DoJ: Accuses Latvia of developing Trickbot malware
While there was some disruption to the gang's activities, the malware group quickly rebuilt its infrastructure and continued to launch new malware campaigns targeting organizations worldwide.
Information source: bleepingcomputer.com
