Thursday, April 17, 2025
HomeRansomwareRomanian Authorities Arrested Two REvil Ransomware RaaS Family Affiliates

Romanian Authorities Arrested Two REvil Ransomware RaaS Family Affiliates

Published on

SIEM as a Service

Follow Us on Google News

Seven users were recently being suspected of using ransomware services on the Internet were arrested, and out of that seven users, five detainees are assumed of having links with the REvil group.

However, among the five detainees, one is a Ukrainian imposed by the United States with ransomware attacks that include the Kaseya attacks which were attributed to REvil.

While Europol affirmed that the suspects are considered to have harmonized more than 5,000 ransomware attacks and they have also forced close to $600,000 from victims.

- Advertisement - Google News

On November 4 an arrest took place which was a  part of a joint operation named as GoldDust, this operation led to the arrest of three other REvil members, and out of the three, two suspects have been connected to GandCrab in Kuwait and South Korea.

DOJ Seizes $6.1M in Ransom Profits

The U.S. Department of Justice (DOJ) opened an accusation that is crediting Yaroslav Vasinskyi, 22, a citizen of Ukrainian, that has been conducting ransomware attacks against multiple victims.

Moreover, the DOJ also stated that they have seized $6.1 million as ransom payments, and this money was being received by Yevgeniy Polyanin, 28, a Russian citizen, who is also charged for conducting several attacks in Texas.

Operation GoldDust

The operation GoldDust was done specifically to arrest the members of REvil ransomware group. The REvil operators pronounced that their infrastructure went down and they are discontinuing their operations for the time being but that will soon come back.

The Europol declared the results of the GoldDust operation, in which it was found that 17 other countries participated in it, with the support of Interpol and Eurojust.

Lastly, during the period of their activity, the threat actors have attacked about 7 thousand users, requesting a total of more than 200 million euros as ransom.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

3 Security Decisions That Could Make or Break Your Career This Year

In today's rapidly evolving digital landscape, security has transcended from being a technical concern...

Harvest Ransomware Attack: Stolen Data Now Publicly Disclosed

French fintech leader Harvest SAS has become the latest high-profile victim of a sophisticated ransomware attack,...

Critical Erlang/OTP SSH Vulnerability Allow Hackers Execute Arbitrary Code Remotely

A major security flaw has been uncovered in the widely used Erlang/OTP SSH implementation,...

Chinese Hacker Group Mustang Panda Bypass EDR Detection With New Hacking Tools

The China-sponsored hacking group, Mustang Panda, has been uncovered by Zscaler ThreatLabz to employ...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Harvest Ransomware Attack: Stolen Data Now Publicly Disclosed

French fintech leader Harvest SAS has become the latest high-profile victim of a sophisticated ransomware attack,...

NetFlow and PCAP Logs Reveal Multi-Stage Attacks In Corporate Networks

In the modern enterprise, network security teams face the daunting challenge of detecting and...

Interlock Ransomware Uses Multi-Stage Attack Through Legitimate Websites to Deliver Malicious Browser Updates

The Interlock ransomware intrusion set has escalated its operations across North America and Europe...