Categories: Ransomware

Romanian Authorities Arrested Two REvil Ransomware RaaS Family Affiliates

Seven users were recently being suspected of using ransomware services on the Internet were arrested, and out of that seven users, five detainees are assumed of having links with the REvil group.

However, among the five detainees, one is a Ukrainian imposed by the United States with ransomware attacks that include the Kaseya attacks which were attributed to REvil.

While Europol affirmed that the suspects are considered to have harmonized more than 5,000 ransomware attacks and they have also forced close to $600,000 from victims.

On November 4 an arrest took place which was a  part of a joint operation named as GoldDust, this operation led to the arrest of three other REvil members, and out of the three, two suspects have been connected to GandCrab in Kuwait and South Korea.

DOJ Seizes $6.1M in Ransom Profits

The U.S. Department of Justice (DOJ) opened an accusation that is crediting Yaroslav Vasinskyi, 22, a citizen of Ukrainian, that has been conducting ransomware attacks against multiple victims.

Moreover, the DOJ also stated that they have seized $6.1 million as ransom payments, and this money was being received by Yevgeniy Polyanin, 28, a Russian citizen, who is also charged for conducting several attacks in Texas.

Operation GoldDust

The operation GoldDust was done specifically to arrest the members of REvil ransomware group. The REvil operators pronounced that their infrastructure went down and they are discontinuing their operations for the time being but that will soon come back.

The Europol declared the results of the GoldDust operation, in which it was found that 17 other countries participated in it, with the support of Interpol and Eurojust.

Lastly, during the period of their activity, the threat actors have attacked about 7 thousand users, requesting a total of more than 200 million euros as ransom.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity, and hacking news updates.

Balaji

BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Recent Posts

DragonForce and Anubis Ransomware Gangs Launch New Affiliate Programs

Secureworks Counter Threat Unit (CTU) researchers have uncovered innovative strategies deployed by the DragonForce and…

2 hours ago

“Power Parasites” Phishing Campaign Targets Energy Firms and Major Brands

Silent Push Threat Analysts have uncovered a widespread phishing and scam operation dubbed "Power Parasites,"…

2 hours ago

Threat Actors Register Over 26,000 Domains Imitating Brands to Deceive Users

Researchers from Unit 42 have uncovered a massive wave of SMS phishing, or "smishing," activity…

3 hours ago

Russian Hackers Attempt to Sabotage Digital Control Systems of Dutch Public Service

The Dutch Defense Ministry has revealed that critical infrastructure, democratic processes, and North Sea installations…

3 hours ago

North Korean APT Hackers Pose as Companies to Spread Malware to Job Seekers

Silent Push Threat Analysts have uncovered a chilling new cyberattack campaign orchestrated by the North…

3 hours ago

North Korean Hackers Exploit GenAI to Land Remote Jobs Worldwide

A groundbreaking report from Okta Threat Intelligence reveals how operatives linked to the Democratic People’s…

3 hours ago