2 May 2023

FBI and Ukrainian cops disrupt nine crypto exchanges used by ransomware actors


FBI and Ukrainian cops disrupt nine crypto exchanges used by ransomware actors

The US Federal Bureau of Investigation (FBI) in cooperation with the National Police of Ukraine have seized domains of nine virtual currency exchange services used by ransomware groups and other cybercriminals for money laundering.

The domains were seized on April 25, 2023, the FBI said in a press release. The disrupted services include 24xbtc.com, 100btc.pro, pridechange.com, 101crypta.com, uxbtc.com, trust-exchange.org, bitcoin24.exchange, paybtc.pro, and owl.gold. The websites provided support both in Russian and English.

“Domain names offered by organizations which were engaged in cryptocurrency conversions and provided assistance to cybercriminals were seized, and related servers were shut down. US based servers used in the scheme were taken offline by US authorities,” the FBI said.

“Many of these services are advertised on online forums dedicated to discussing criminal activity. By providing these services, the virtual currency exchanges knowingly support the criminal activities of their clients and become co-conspirators in criminal schemes,” the agency added.

The FBI said that the investigation is ongoing, without sharing further details on the operation.


Back to the list

Latest Posts

Cyber Security Week in Review: November 1, 2024

Cyber Security Week in Review: November 1, 2024

In brief: Hackers are exploiting critical zero-day flaw in PTZ cameras, the Dstat.cc DDoS service disrupted by law enforcement, and more.
1 November 2024
North Korean hackers caught collaborating with Play ransomware

North Korean hackers caught collaborating with Play ransomware

The theory is that Andariel is either working as an affiliate of Play ransomware or serving as an initial access broker.
31 October 2024
Large-scale phishing campaign targeting Ukraine's taxpayers

Large-scale phishing campaign targeting Ukraine's taxpayers

The attack deploys the Litemanager RMT, which provides unauthorized access to the infected computer.
30 October 2024