The China Mail - Global operation smashes 'most harmful cyber crime group'

USD -
AED 3.672501
AFN 64.498937
ALL 81.74754
AMD 363.015104
ANG 1.790365
AOA 916.999844
ARS 1516.502497
AUD 1.43247
AWG 1.8025
AZN 1.705152
BAM 1.744856
BBD 2.013944
BDT 123.295432
BGN 1.683441
BHD 0.377736
BIF 2991.778964
BMD 1
BND 1.280405
BOB 11.844107
BRL 5.002394
BSD 0.999924
BTN 96.667826
BWP 13.756033
BYN 3.041855
BYR 19600
BZD 2.011089
CAD 1.42277
CDF 2315.000163
CHF 0.83113
CLF 0.024752
CLP 977.402243
CNY 6.702298
CNH 6.69272
COP 3221.83
CRC 456.246627
CUC 1
CUP 23.99868
CVE 98.37316
CZK 21.746597
DJF 178.059889
DKK 6.67093
DOP 60.602816
DZD 134.60339
EGP 52.376501
ERN 15
ETB 162.459731
EUR 0.89241
FJD 2.24725
FKP 0.757083
GBP 0.756385
GEL 2.606653
GGP 0.757083
GHS 11.754105
GIP 0.757083
GMD 74.000004
GNF 8796.620528
GTQ 7.644716
GYD 209.141639
HKD 7.84765
HNL 26.83992
HRK 6.722796
HTG 130.93884
HUF 325.767036
IDR 17909
ILS 3.05766
IMP 0.757083
INR 96.71395
IQD 1514.847378
IRR 1732150.000161
ISK 122.079953
JEP 0.757083
JMD 158.703536
JOD 0.708983
JPY 158.251973
KES 129.78026
KGS 87.449892
KHR 4060.166475
KMF 439.999942
KPW 900.000318
KRW 1341.159835
KWD 0.31082
KYD 0.833266
KZT 454.380002
LAK 22423.152927
LBP 89543.891265
LKR 330.845716
LRD 170.989125
LSL 16.543418
LTL 2.95274
LVL 0.60489
LYD 6.429683
MAD 9.819027
MDL 17.92861
MGA 4458.976612
MKD 54.92981
MMK 2099.693915
MNT 3600.849225
MOP 8.082417
MRU 39.958604
MUR 47.460049
MVR 15.409973
MWK 1733.851363
MXN 18.197895
MYR 4.085939
MZN 63.890359
NAD 16.543713
NGN 1329.801015
NIO 36.801278
NOK 9.562975
NPR 154.668165
NZD 1.78121
OMR 0.384492
PAB 0.999915
PEN 3.429255
PGK 4.533917
PHP 62.822501
PKR 276.897808
PLN 3.91195
PYG 5687.419428
QAR 3.654847
RON 4.765901
RSD 104.783985
RUB 84.794289
RWF 1473.918047
SAR 3.754524
SBD 8.081105
SCR 13.822303
SDG 601.502131
SEK 9.96595
SGD 1.28036
SHP 0.755886
SLE 24.624993
SLL 20969.491881
SOS 571.420924
SRD 37.650502
STD 20697.981008
STN 21.857728
SVC 8.749336
SYP 13002.000254
SZL 16.540206
THB 33.531499
TJS 9.199181
TMT 3.5
TND 2.984222
TOP 2.40776
TRY 49.342505
TTD 6.792847
TWD 31.901098
TZS 2640.650076
UAH 44.910719
UGX 4088.733456
UYU 40.164333
UZS 11899.525821
VES 873.638703
VND 25881
VUV 120.049533
WST 2.785534
XAF 585.382433
XAG 0.016574
XAU 0.000239001452
XCD 2.70255
XCG 1.802139
XDR 0.707052
XOF 585.382433
XPF 106.398069
YER 236.149789
ZAR 16.53323
ZMK 9001.20116
ZMW 19.873405
ZWL 321.999592
SSP 5753.260075
MXV 2.055904
  • RYCEF

    0.4000

    19.71

    +2.03%

  • CMSC

    0.0000

    20.4

    0%

  • BTI

    0.4200

    56.05

    +0.75%

  • BP

    0.2800

    44.43

    +0.63%

  • RBGPF

    1.6000

    67

    +2.39%

  • RIO

    -0.1500

    94.41

    -0.16%

  • AZN

    -0.4300

    166.15

    -0.26%

  • GSK

    0.4600

    49.7

    +0.93%

  • BCE

    -0.4100

    20.56

    -1.99%

  • NGG

    -0.2500

    75.24

    -0.33%

  • VOD

    -0.0400

    16.58

    -0.24%

  • RELX

    -0.4500

    33.07

    -1.36%

  • BCC

    -0.5500

    76.59

    -0.72%

  • CMSD

    -0.0300

    20.27

    -0.15%

  • JRI

    -0.2500

    10.77

    -2.32%

Global operation smashes 'most harmful cyber crime group'
Global operation smashes 'most harmful cyber crime group' / Photo: © NATIONAL CRIME AGENCY/AFP

Global operation smashes 'most harmful cyber crime group'

An international operation led by UK and US law enforcement has severely disrupted "the world's most harmful cybercrime group", the Russian-linked ransomware specialist LockBit, officials announced Tuesday.

Text size:

LockBit and its affiliates have targeted governments, major companies, schools and hospitals, causing billions of dollars of damage and extracting tens of millions in ransoms from victims.

Britain's National Crime Agency (NCA), working with the Federal Bureau of Investigation, Europol and agencies from nine other countries in Operation Cronos, said it had infiltrated LockBit's network and taken control of its services.

"We have hacked the hackers, we have taken control of their infrastructure, seized their source code, and obtained keys that will help victims decrypt their systems," NCA director general Graeme Biggar told reporters in London.

LockBit's website -- selling services that allow people to organise cyber attacks and hold data until a ransom is paid appears -- was taken over on Monday evening.

A message appeared on the site stating that it was "now under control of law enforcement".

"As of today LockBit is effectively redundant, LockBit has been locked out," Biggar said.

The US Justice Department (DOJ) said the agencies had seized control of "numerous public-facing websites used by LockBit to connect to the organization's infrastructure" and taken control of servers used by LockBit administrators.

The NCA added that it had obtained more than 1,000 decryption keys and will be contacting UK-based victims in the coming days and weeks to offer support and help them recover encrypted data.

Biggar said the network had been behind 25 percent of all cyber attacks in the past year.

LockBit has targeted over 2,000 victims and received more than $120 million in ransom payments since it formed four years ago, according to the DOJ.

Those targeted have included Britain's Royal Mail, US aircraft manufacturer Boeing, and a Canadian children's hospital.

In January 2023, US law enforcers shut down the Hive ransomware operation which extorted some $100 million from more than 1,500 victims worldwide.

Since then, LockBit has been seen as the biggest current threat.

- Dark Web -

Hive and LockBit are part of what cybersecurity experts call a "ransomware as a service" style, or RaaS -- a business that leases its software and methods to others to use in extorting money.

Ariel Ropek, director of cyber threat intelligence at cybersecurity firm Avertium, told AFP last year that this structure makes it possible for criminals with minimal computer fluency to get into ransomware by paying others for their expertise.

On the so-called dark web, providers of ransomware services pitch their products openly.

At one end are the initial access brokers, who specialise in breaking into corporate or institutional computer systems.

They then sell that access to the hacker, or ransomware operator.

But the operator depends on RaaS developers like Hive or LockBit, which have the programming skills to create the malware needed to carry out the operation.

Typically, their programmes -- once inserted by the ransomware operator into a target's IT systems -- are manipulated to freeze, via encryption, the target's files and data.

RaaS developers offer a full service to the operators, for a large share of the ransom paid out, said Ropek.

When the ransomware is planted and activated, the target receives a message telling them how much to pay to get their data unencrypted.

That ransom can run from thousands to millions of dollars.

On Tuesday, the US unsealed an indictment against two Russian nationals, bringing to five the number of Russians it has charged in connection with LockBit.

In a separate notice, the US Treasury Department said it is imposing sanctions on the pair, affiliates of LockBit, who "actively engaged" in ransomware attacks.

Biggar said a "large concentration" of the cyber criminals are in Russia and are Russian-speaking, but law enforcement agencies have not seen any direct support for LockBit from the Russian state.

"There is clearly some tolerance of cyber criminality within Russia," he added.

G.Tsang--ThChM