AP

Ukraine police seize cash in raids on major ransomware gang

Jun 16, 2021, 3:13 PM | Updated: 5:05 pm

MOSCOW (AP) — Ukrainian police have carried out nearly two dozen raids targeting alleged associates of a Russian-speaking ransomware gang it blamed for a half billion dollars in cyberattacks and extortion that hit the United States and South Korea especially hard.

A police statement on Wednesday said 21 raids were conducted on the homes of suspects affiliated with the Clop ransomware syndicate in Kyiv and elsewhere, with computer equipment and about 5 million hryna ($185,000) in cash seized.

Six defendants carried out attacks on U.S. and Korean companies — for which they face up to eight years in prison for violating computer crime and money-laundering laws, the statement said. It did not say whether any suspects were detained, and said the investigation was ongoing. The Clop dark web leak site remained online hours after the raids were announced, suggesting the gang’s internet infrastructure might still be intact.

The most potent ransomware gangs operate with Kremlin tolerance, based out of reach of Western law enforcement. Russia neither prosecutes not extradites them. Trying to persuade its president, Vladimir Putin, to change that was a priority of U.S. President Joe Biden in their meeting Wednesday in Geneva. It’s not clear whether Biden made any headway.

Video posted by the Ukrainian police showed Korean police taking part in this week’s raids, where cash, cell phones and cars were also seized. The police statement said four Korean companies hit by the gang with the ransomware — which scrambles data that can only be unlocked with a software key obtained by paying the criminals — had paid ransoms. It said the gang targeted U.S. universities, including Stanford Medical School and the University of Maryland.

Wednesday’s raid “is a continuation of the much more aggressive posture that law enforcement has taken against ransomware gangs this year,” said analyst Allan Liska of the cybersecurity firm Recorded Future. “It really does feel like law enforcement has figured out how to attack the ransomware scourge, and hopefully, will slow down the attacks.”

After last month’s attack on the Colonial Pipeline affected fuel shipments to the U.S. East Coast, the White House began taking ransomware criminals as seriously as it does terrorists, and many are now lying low. The author of the Colonial attack went into hiding and a different group, Avaddon, suddenly announced its retirement. Cybersecurity analysts caution, however, that such retirements are not new and can be a ruse to thwart law enforcement while the criminals reconstitute and create new products with different brands.

And while some arrests have been made and ransomware infrastructure disabled in recent months, no kingpins have been snared.

Clop is among the more prolific ransomware gangs, known for extorting victims by threatening to publish data stolen from them. It has published the names of 65 victims to its dark web extortion site since August, said Liska.

In some cases, Clop has extorted victims with data it may not have obtained directly but purchased instead from third party cyberthieves. It’s what security researchers suspect happened in the case of the Universities of Colorado and Miami, the rail transport company CSX Corporation, the Kroger grocery and pharmacy chain, the Canadian aircraft maker Bombardier and the prominent law firm Jones Day. That data was stolen in the hack of a software tool made by the California firm Accellion, used to manage large email attachments.

___

Bajak reported from Boston

Copyright © The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.

AP

Republican presidential candidates, from left, former Arkansas Gov. Asa Hutchinson, former New Jers...

Associated Press

3rd Republican presidential debate is set for Nov. 8 in Miami, with the strictest qualifications yet

The third Republican presidential debate will be held in Miami on Nov. 8, a day after several states hold off-year elections.

3 days ago

During the equinox, the Earth’s axis and its orbit line up so that both hemispheres get an equal ...

Associated Press

The fall equinox is here. What does that mean?

The equinox arrives on Saturday, marking the start of the fall season for the Northern Hemisphere. But what does that actually mean?

3 days ago

Ray Epps Ray Epps, an Arizona man who became the center of a conspiracy theory about Jan. 6, 2021, ...

Associated Press

Ray Epps, an Arizona man who supported Trump, pleads guilty to Capital riot charge

Ray Epps, the target of a conspiracy theory about the Jan. 6, 2021, attack, pleaded guilty on Wednesday to a misdemeanor charge.

5 days ago

Former President Donald Trump repeatedly declined in an interview aired Sunday, Sept. 17, 2023, to ...

Associated Press

Trump refuses to say in a TV interview how he watched the Jan. 6 attack unfold at the US Capitol

Former President Donald Trump repeatedly declined in an interview aired Sunday to answer questions about whether he watched the Capitol riot.

8 days ago

This frame grab from video, provided by the Mexican government, shows Ovidio Guzman Lopez being det...

Associated Press

Mexico extradites son of ‘El Chapo,’ Ovidio Guzman Lopez to US

The son of notorious cartel leader Joaquin “El Chapo” Guzmán, Ovidio Guzman Lopez was extradited to the U.S. on Friday.

9 days ago

impeachments in US history...

Associated Press

A look at notable impeachments in US history, including Texas Attorney General Ken Paxton

Texas Attorney General Ken Paxton was acquitted Saturday on during his impeachment trial. Here's a roundup of impeachments in U.S. history.

9 days ago

Sponsored Articles

Sanderson Ford...

Sanderson Ford

Sanderson Ford congratulates D-backs’ on drive to great first half of 2023

The Arizona Diamondbacks just completed a red-hot first half of the major league season, and Sanderson Ford wants to send its congratulations to the ballclub.

...

Ability360

At Ability360, every day is Independence Day

With 100 different programs and services, more than 1,500 non-medically based home care staff, a world-renowned Sports & Fitness Center and over 15,000 people with disabilities served annually, across all ages and demographics, Ability360 is a nationwide leader in the disability community.

...

OCD & Anxiety Treatment Center

5 mental health myths you didn’t know were made up

Helping individuals understand mental health diagnoses like obsessive compulsive spectrum disorder or generalized anxiety disorder isn’t always an easy undertaking. After all, our society tends to spread misconceptions about mental health like wildfire. This is why being mindful about how we talk about mental health is so important. We can either perpetuate misinformation about already […]

Ukraine police seize cash in raids on major ransomware gang