HomeSecurityClop ransomware: More information revealed

Clop ransomware: More information revealed

More details have been revealed about a 30-month investigation aimed at disrupting the operations of the Clop ransomware group.

Clop ransomware

See also: USA: Reward for information on the Darkside ransomware gang

In June, Ukrainian police arrested six suspects in 20 raids across Kiev and other cities, seizing computers, technology, cars and about $185,000.

The Ukrainian National Police collaborated with law enforcement authorities in South Korea for the raid, now known as Operation Cyclone.

Interpol, an intergovernmental organization focused on facilitating coordinated activities between police agencies worldwide, said last week that the operation was being managed by Interpol's Cyber ​​Fusion Center in Singapore.

Trend Micro, CDI, Kaspersky Lab, Palo Alto Networks, Fortinet, and Group-IB contributed information through the Interpol Gateway project, along with law enforcement officials from Ukraine, South Korea, and the United States.

South Korean companies S2W LAB and KFSI also contributed to the analysis of Dark Web activity.

See also: Phishing emails infect victims with MirCop ransomware

South Korea was particularly interested in the arrests due to Clop's alleged involvement in a ransomware attack against E-Land. The ransomware operators told Bleeping Computer that point-of-sale (PoS) malware had been implanted in the Korean retail giant's systems for about a year, leading to the theft of millions of credit cards.

Clop is one of several ransomware gangs operating leak sites on the Dark Web. The groups will claim responsibility for a ransomware attack and use these platforms for two purposes: to facilitate communication with a victim to negotiate a ransom payment in exchange for a decryption key — and to further extort by threatening to leak stolen sensitive data if payment is not made.

Clop had previously exploited zero-day vulnerabilities in the Accellion File Transfer Appliance (FTA) software, along with other threat actors, to claim high-profile victims, including the Reserve Bank of New Zealand, the Washington State Auditor, Qualys, and Stanford School of Medicine.

The six suspects are also charged with money laundering, as Clop is believed to have laundered at least $500 million obtained from ransomware activities. If convicted as members of the notorious group, the defendants face up to eight years in prison.

See also: CERT-FR: Warns of Lockean ransomware attacks against French companies

However, it should be noted that the six arrests in Ukraine have not stopped the activities of the Clop ransomware group or disrupted its leak website. The main operators of the ransomware are believed to be based in Russia.

Interpol added that Operation Cyclone “continues to provide evidence that fuels further cybercrime investigations and allows the international police community to disrupt numerous channels used by cybercriminals to launder cryptocurrency.”

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS