The global cybercrime gang ‘Hive’ has reportedly been dismantled

According to Europol, a dangerous gang of cybercriminals has been dismantled in Ukraine. The group is said to have carried out ransomware attacks worldwide.

Cybercrime exposed: The gang from Ukraine attacked the servers of large companies or organizations in more than seventy countries and caused hundreds of millions of euros in damage, Europol announced in The Hague on Tuesday.

Despite the ongoing war in Ukraine, about thirty buildings were searched on Tuesday. According to Europol, the alleged gang leader (32) and his four main accomplices were arrested. They are said to be part of a network that is held responsible for large-scale ransomware attacks.

Action of cyber criminals

According to Europol, the gang placed malicious software in the servers, blocking data and systems. Data and systems were only released after large amounts of ransoms had been paid.

The criminals used the ransomware programs LockerGoga, MegaCortex, HIVE and Dharma, among others, to carry out their attacks.

The researchers discovered that more than 250 servers of large companies or organizations had been attacked. The operation involved Europol and the judicial authority Eurojust in The Hague, as well as investigators from seven countries, including Germany and Switzerland.

In this country, according to a Europol announcement, the Federal Police Office (Fedpol), the Basel-Landschaft Police, the Public Prosecutor’s Office of the Canton of Zurich and the Cantonal Police of Zurich were involved.

According to the information, the investigations started in 2019 at the initiative of France. The first arrests and searches took place in 2021.

“An important impetus for the current success was provided by investigations by the police headquarters in Reutlingen, which became public in January 2023. At that point, the technical infrastructure was destroyed and a Hive darknet site was shut down. According to a spokesperson for the Stuttgart public prosecutor’s office, it was possible to gain access to the hackers’ chats and data and thus ultimately identify the suspects.

As “Spiegel” writes, researchers suspect that many ransomware extortionists operate from Russia. That’s why the “shutdown banner” on Hive’s darknet page was probably also published in Russian.

Sources

  • Press agency DPA
  • europol.europa.eu: International collaboration leads to dismantling of ransomware group in Ukraine amid ongoing war (November 28, 2023)
  • spiegel.de: Investigators arrest suspected hackers in Ukraine

(t-online/dsc)

Source: Watson

follow:
Ella

Ella

I'm Ella Sammie, author specializing in the Technology sector. I have been writing for 24 Instatnt News since 2020, and am passionate about staying up to date with the latest developments in this ever-changing industry.

Related Posts