HomeSecurityDoppelPaymer ransomware: Suspect arrested in Moldova

DoppelPaymer ransomware: Suspect arrested in Moldova

Moldovan authorities have arrested a 45-year-old man who allegedly participated in ransomware against organizations cyberattacks in the Netherlands in 2021. The man is linked to the notorious DoppelPaymer ransomware group , which is responsible for significant digital intrusions aimed at extorting victims.

DoppelPaymer ransomware Moldova

The operation took place on May 6, when police authorities searched the suspect's residence and vehicle. During the on-site inspection, significant items were seized, including two laptops, a tablet, a mobile phone, six bank cards, various storage drives, an electronic wallet and 84,800 euros.

The suspect remains in custody, while extradition proceedings to the Netherlands, according to a statement from the Moldovan prosecutor's office. The arrest was carried out as part of a coordinated operation involving the Center Cybercrime and Dutch security authorities.

See also: Hackers hide ransomware in JPG images

According to a statement issued on Monday, the 45-year-old is accused of orchestrating the 2021 ransomware attack (DoppelPaymer) against the Dutch Research Council (NWO), causing damages estimated at 4.5 million euros. The NWO had disclosed the cyberattack on February 14 of that year, noting that it was forced to suspend its funding application system.

Ten days later, cybercriminals published stolen files from the organization on the DoppelPaymer group's leak siteon the dark web, after the NWO refused to pay the ransom.

The DoppelPaymer group emerged in 2019 as an offshoot of the Evil Corp criminal group, with which it shares technical characteristics and code. The DoppelPaymer perpetrators are known for their double-pressure: on the one hand, they threaten to leak data in case of refusal to pay, and on the other, they delete the decryption keys if victims turn to professional negotiators for better terms of recovery.

As early as 2020, the Federal Bureau of Investigation (FBI) warned that ransomware perpetrators don’t stop at encrypting data. According to an internal bulletin from that year, before installing malware, attackers steal sensitive information that they then use as leverage in extortion campaigns. In some cases, victims even receive personal phone calls, with the aim of further pressuring them to pay the ransom.

See also: New Mamona ransomware targets Windows systems

The group behind the DoppelPaymer ransomware is among the pioneers of this tactic. From its inception until 2022, it launched attacks on large business groups and critical infrastructures internationally. During this time, the gang rebranded at least twice, renaming its operations to Grief (or Pay or Grief) and Entropy, while maintaining the same basic techniques and codes.

DoppelPaymer ransomware: Suspect arrested in Moldova

Police pressure on the network increased in 2023, when authorities issued arrest warrants for five key members of the organization. Two of them are considered important figures in the group and were placed on international wanted lists in March of that year.

DoppelPaymer's list of victims includes some of the most recognizable names in business and government. Among them: Foxconn , one of the world's largest electronics manufacturers; Kia Motors America ; the Delaware County government in Pennsylvania; Taiwanese laptop manufacturer Compal ; and Newcastle University in the United Kingdom.

See also: Ransomware groups abuse legitimate Kickidler software

Protection from ransomware attacks

  • Stay up to date on the latest ransomware trends and tactics used by attackers
  • Implement multi-factor authentication (MFA) for all user accounts
  • Enable firewall on all devices connected to your network
  • Keep sensitive data encrypted
  • Update all your devices and systems with the latest security patches
  • Conduct regular security audits and penetration testing
  • Use strong, unique passwords and change them regularly.
  • Limit user access to only necessary systems and information
  • Consider using solutions email security for additional protection against phishing attacks
  • Have a recovery plan to quickly restore systems in the event of an attack
  • Back up your data regularly

Source: www.bleepingcomputer.com

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS