17 June 2021

Clop ransomware gang members arrested in Ukraine


Clop ransomware gang members arrested in Ukraine

An international operation conducted by Ukrainian police in conjunction with law enforcement officers from the United States and the Republic of Korea led to arrest of six members of the Clop ransomware gang.

The suspects have been accused of running a double extortion scheme, threatening to leak victims’ sensitive information if ransom demand is not paid.

According to the National Police of Ukraine, victims included Stanford University’s Medical School, the University of Maryland, the University of California and a number of unnamed Korean organizations.

The attacks involved the use of the Clop ransomware, as well as other hacking tools, such as Cobalt Strike and FlawedAmmyy RAT causing estimated damages of up to $500 million, the Ukrainian police said in a statement.

The police have carried out 21 raids in the Ukrainian capital of Kyiv, including the homes of the defendants, resulting in the seizure of computer equipment, luxury cars, and 5 million hryvnias ($184,679) in cash. The law enforcement also shut down the infrastructure used to spread the malware and blocked channels for legalizing criminally acquired cryptocurrencies.

At present, it is not clear if the arrested individuals are affiliates or core members of the Clop ransomware operation. If convicted, each defendant faces up to eight years in prison for violating computer crime and money-laundering laws.

Back to the list

Latest Posts

Cyber Security Week in Review: April 26, 2024

Cyber Security Week in Review: April 26, 2024

In brief: Cisco and CrushFTP patch zero-days, researchers sinkhole C&C server used by PlugX malware, and more.
26 April 2024
US charges Samourai cryptomixer founders with laundering $100 million

US charges Samourai cryptomixer founders with laundering $100 million

The cryptocurrency mixer facilitated over $2 billion in illegal transactions.
25 April 2024
ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

ArcaneDoor state-sponsored malware campaign strikes Cisco networking gear

The attackers exploited two zero-day vulnerabilities in Cisco networking equipment.
25 April 2024