-
Rushdie assailant convicted of terrorism charges
-
Samsung operating profit up 1,800% in second quarter on AI boom
-
Australian regulator says Telegram breached online safety law
-
De Zerbi wants Bergvall at Spurs, but can't promise starting role
-
New Zealand foreign minister in racism row with Chinese ambassador
-
De Minaur tops Tsitsipas to set up Hewitt clash in Washington
-
Messi returns to Miami training after World Cup break
-
Japanese population below 120 million for first time in decades
-
Idi Amin's grandson disqualified from Commonwealth boxing bout
-
Meta misses profit expectations, sticks to massive AI spending
-
O'Connor wins Commonwealth heptathlon as Australia set new record for swimming golds
-
Inequality best predicts how nations handle pandemics: study
-
De Minaur beats Tsitsipas to set up Hewitt clash in Washington
-
Brazil's Jair Bolsonaro denies authorizing deepfake for election message
-
Nigeria dismantles meth lab, but fears of Mexican cartel links linger
-
Boaduwaa strikes as Ghana beat WAFCON debutants Cape Verde
-
FIFA proposal 'an opportunity but not an obligation', says Infantino
-
US actor Jared Leto denies latest accusations of sexual assault
-
Campari - king of the spritz - hopes to conquer American heartland
-
Danube drops to 'historic lows' as fresh heatwave hits
-
Mancini wants Italy back to trophy-winning ways
-
US Federal Reserve holds rates steady as inflation hawks call for hike
-
Torrey Pines added to new PGA Tour top-level series from 2028
-
Eala beats defending champ Fernandez in Washington
-
Air France-KLM and Lufthansa bid for Portugal's TAP airline
-
US man accused of destroying evidence by wiping phone at airport
-
Korda seeks 'control' as she chases history at women's British Open
-
BTS pulls out of Grammys after Asian pop category introduction
-
Profits soar at Airbus as it delivers more planes
-
Judge orders Amy Winehouse's father to pay nearly £1mn to her friends
-
US-Saudi strikes in Iraq kill 20, including Iranians
-
Crisis-hit Cuba opens pharmacies, gas stations to private firms
-
Brazil court scrutinizes Jair Bolsonaro deepfake endorsing son
-
Pro-Kremlin TV commentator ordered to leave France, under house arrest
-
OpenAI says rogue AI agent attack hit other companies
-
'I started crying': Battle to tame fresh blaze near French seaside
-
Irish singer, musician Glen Hansard killed in motorbike crash at 56
-
Former top US Covid expert Fauci declines to answer hostile Senate questioning
-
Ukraine appeals against Russian return to Olympics
-
Neymar says his time playing for Brazil 'is over'
-
Rheinmetall shares surge after armsmaker reports record profit
-
F1 boss says season to finish in Europe if Gulf races cancelled
-
Israel army hit Gaza mosque, says used for Hamas 'weapons storage'
-
Spanish wildfire evacuees go home as France hit by new heat alert
-
Trump says US to hit Iran hard
-
French DJ Kavinsky, famed for 'Nightcall', found dead in Paris
-
UBS second-quarter net profit up 17% to $2.8 billion
-
How an AFP beach snap became emblem of Europe's wildfire summer
-
FIFA hit by furious backlash over plans to sell stake in competitions
-
More than half of England 'officially in drought': UK govt
Global operation smashes 'most harmful cyber crime group'
An international operation led by UK and US law enforcement has severely disrupted "the world's most harmful cybercrime group", the Russian-linked ransomware specialist LockBit, officials announced Tuesday.
LockBit and its affiliates have targeted governments, major companies, schools and hospitals, causing billions of dollars of damage and extracting tens of millions in ransoms from victims.
Britain's National Crime Agency (NCA), working with the Federal Bureau of Investigation, Europol and agencies from nine other countries in Operation Cronos, said it had infiltrated LockBit's network and taken control of its services.
"We have hacked the hackers, we have taken control of their infrastructure, seized their source code, and obtained keys that will help victims decrypt their systems," NCA director general Graeme Biggar told reporters in London.
LockBit's website -- selling services that allow people to organise cyber attacks and hold data until a ransom is paid appears -- was taken over on Monday evening.
A message appeared on the site stating that it was "now under control of law enforcement".
"As of today LockBit is effectively redundant, LockBit has been locked out," Biggar said.
The US Justice Department (DOJ) said the agencies had seized control of "numerous public-facing websites used by LockBit to connect to the organization's infrastructure" and taken control of servers used by LockBit administrators.
The NCA added that it had obtained more than 1,000 decryption keys and will be contacting UK-based victims in the coming days and weeks to offer support and help them recover encrypted data.
Biggar said the network had been behind 25 percent of all cyber attacks in the past year.
LockBit has targeted over 2,000 victims and received more than $120 million in ransom payments since it formed four years ago, according to the DOJ.
Those targeted have included Britain's Royal Mail, US aircraft manufacturer Boeing, and a Canadian children's hospital.
In January 2023, US law enforcers shut down the Hive ransomware operation which extorted some $100 million from more than 1,500 victims worldwide.
Since then, LockBit has been seen as the biggest current threat.
- Dark Web -
Hive and LockBit are part of what cybersecurity experts call a "ransomware as a service" style, or RaaS -- a business that leases its software and methods to others to use in extorting money.
Ariel Ropek, director of cyber threat intelligence at cybersecurity firm Avertium, told AFP last year that this structure makes it possible for criminals with minimal computer fluency to get into ransomware by paying others for their expertise.
On the so-called dark web, providers of ransomware services pitch their products openly.
At one end are the initial access brokers, who specialise in breaking into corporate or institutional computer systems.
They then sell that access to the hacker, or ransomware operator.
But the operator depends on RaaS developers like Hive or LockBit, which have the programming skills to create the malware needed to carry out the operation.
Typically, their programmes -- once inserted by the ransomware operator into a target's IT systems -- are manipulated to freeze, via encryption, the target's files and data.
RaaS developers offer a full service to the operators, for a large share of the ransom paid out, said Ropek.
When the ransomware is planted and activated, the target receives a message telling them how much to pay to get their data unencrypted.
That ransom can run from thousands to millions of dollars.
On Tuesday, the US unsealed an indictment against two Russian nationals, bringing to five the number of Russians it has charged in connection with LockBit.
In a separate notice, the US Treasury Department said it is imposing sanctions on the pair, affiliates of LockBit, who "actively engaged" in ransomware attacks.
Biggar said a "large concentration" of the cyber criminals are in Russia and are Russian-speaking, but law enforcement agencies have not seen any direct support for LockBit from the Russian state.
"There is clearly some tolerance of cyber criminality within Russia," he added.
O.Farraj--SF-PST