BKA Nabs REvil Masterminds Behind German Ransomware Spree

BKA Nabs REvil Masterminds Behind German Ransomware Spree

German federal police (BKA) have reportedly identified key figures linked to the REvil ransomware gang, attributing responsibility for a massive wave of over 130 ransomware attacks targeting businesses across Germany. Cyber Threat Intelligence shared this development, highlighting the BKAโ€™s successful efforts to dismantle operations behind these significant intrusions.

The investigation, which appears to have been ongoing, has led to the identification of individuals believed to be orchestrating these attacks. While specific details on the arrests or the extent of the disruption remain scarce, the BKAโ€™s success signals a win for law enforcement against a notorious ransomware-as-a-service (RaaS) operation. REvil has been a persistent threat, known for its high-profile attacks and significant financial demands.

What This Means For You

  • Organizations should proactively review and harden their defenses against ransomware, particularly focusing on robust endpoint detection and response (EDR) solutions and regular, verified offline backups, given the persistent threat posed by groups like REvil.
๐Ÿ”Ž
Is your vendor affected? Start hunting now. Search by organization or domain, set watchlist alerts, and get notified when your third parties are compromised.
Open Intel Bot โ†’

Related coverage

Flipper Devices Seeks Community for Flipper One Linux Platform

Flipper Devices, the company behind the widely used Flipper Zero penetration testing tool, is actively soliciting community assistance for its new endeavor: Flipper One. This...

threat-inteldata-breachmalwaretools
/SCW Research /MEDIUM

New Breaches Expose Sensitive Business Data, PII for Targeted Attacks

DARKFEED reports a significant week for data breaches, with several incidents exposing critical information. One large company suffered a leak that could include highly sensitive...

darkwebthreat-intelransomwarevulnerabilitydata-breach
/SCW Vulnerability Desk /MEDIUM /⚑ 3 IOCs /⚙ 3 Sigma

Microsoft Defender Zero-Days Under Active Exploitation

Microsoft has issued patches for two zero-day vulnerabilities in Defender, both of which are actively being exploited in attacks. BleepingComputer reports that these critical flaws...

threat-inteldata-breachmalwarevulnerabilitymicrosoft
/SCW Vulnerability Desk /MEDIUM /⚑ 1 IOC /⚙ 3 Sigma