[ad_1]
Wednesday, as US President Joe Biden and Russian President Putin are preparing to meet in Geneva. Ukrainian law enforcement agencies announced the arrest of six suspects in connection with the notorious Cl0p Ransomware group. The Ukrainian authorities, in cooperation with South Korean and American investigators, searched 21 homes in and around Kiev, seized computers, smartphones and servers, and recovered US$184,000, believed to be a ransom.
As the ransomware crisis continues to escalate, Cl0p’s arrest constitutes a very rare success story. Since 2019, the organization has accumulated several high-profile victims, including Stanford University School of Medicine, the University of California, and South Korean e-commerce giant E-Land.And hackers Seems to cooperate or have contact with them Other cybercriminal organizations, such as financial crime syndicates FIN11 And what is known as a malware distribution organization TA505However, the collaborative law enforcement process that led to the deletion also underscores why blocking the wider ransomware threat is still a distant dream. This time Ukraine is willing to help, but until Russia does so, this situation will hardly change.
Most of the ransomware actors that have caused severe damage in recent months have been operating outside Russia, including Luc, A large-scale hospital hacking was carried out in the United States last year, Dark side, which one Dismantled the colonial pipeline Last month, and recently hit Global meat supplier JBS with Quanta ComputerThe Ministry of Justice has prosecuted Russian ransomware attackers, but it is difficult to really arrest them. Putin has stated publicly for years—including an interview that was frequently quoted in an interview with NBC in 2016—as long as cybercriminals did not violate Russian law, he had no interest in prosecuting them.
“If you are not strict in law enforcement in any area of any country/region, then there will definitely be enough people who want to do illegal activities there,” said Craig Williams, Cisco Talos Outreach Director . “We have not only these areas in Europe, but also effective safe havens for cybercriminals in South America and other regions. So what we end up with is this model of aggression, which is allowed to target private companies and civilians online, and really Can’t see the end.”
Russia has turned a blind eye to cybercrime for many years, but the shameless state-backed hacking of the Kremlin, from election interference to widespread espionage, has generally attracted more attention. However, in the past 18 months, the severity and frequency of global ransomware attacks have changed from an ongoing problem to an urgent crisis. Attacks on critical infrastructure and supply chains paint a dire prospect for ransomware attackers to make money.
Tracking down the culprits is usually not as difficult as arresting them.U.S. has Prosecute multiple Russian hackers, And even managed to seize the millions of dollars in ransom paid by the colony pipeline. But acting on this information usually requires international cooperation. Russia does not have an extradition treaty with the United States, and it seems that it has deliberately refused to help. On June 3 and June 3, the Assistant Attorney General of the United States Department of Justice, John Demers, stated that, in fact, the Department of Justice did not bother to seek assistance from Russian law enforcement to track colonial pipeline hackers. Released on Wednesday.
[ad_2]
Source link






