BKA Nabs REvil Suspects Linked to German Ransomware Spree

BKA Nabs REvil Suspects Linked to German Ransomware Spree

German authorities, specifically the Federal Criminal Police Office (BKA), have unmasked two individuals suspected of operating REvil ransomware.

According to Cyber Threat Intelligence, these operators are believed to be behind a significant wave of over 130 ransomware attacks targeting businesses across Germany. The BKAโ€™s investigation, which has been ongoing, culminated in the identification and apprehension of these key figures in the ransomware ecosystem. This development marks a notable success for law enforcement in disrupting the activities of major ransomware gangs.

The REvil ransomware strain has been a persistent threat, known for its sophisticated operations and high-profile attacks. The BKAโ€™s action against these alleged operators underscores the ongoing global effort to dismantle such criminal enterprises and bring those responsible for widespread digital extortion to justice. Further details regarding the extent of their operations and any recovered assets are expected to emerge as the investigation progresses.

What This Means For You

  • Given the persistence of ransomware operations like REvil, organizations should ensure their incident response plans include specific playbooks for ransomware, focusing on rapid containment and robust, tested backups that are isolated from the primary network.
๐Ÿ”Ž
Is your vendor affected? Start hunting now. Search by organization or domain, set watchlist alerts, and get notified when your third parties are compromised.
Open Intel Bot โ†’

Related coverage

Google Accidentally Exposes Chromium RCE Flaw Details

Google has inadvertently leaked critical details about an unfixed vulnerability in Chromium, as reported by BleepingComputer. This flaw allows JavaScript to persist and execute in...

threat-inteldata-breachmalware
/SCW Research /HIGH /⚙ 3 Sigma

Showboat Linux Malware Targets Middle East Telecom with SOCKS5 Proxy

The Hacker News reports that a new Linux malware, named Showboat, has been actively deployed since mid-2022. This modular post-exploitation framework is designed to compromise...

threat-intelvulnerabilitymalwaretools
/SCW Vulnerability Desk /HIGH /⚑ 5 IOCs

Crypto Drainers Scale Wallet Theft via Phishing and Automation

Modern cryptocurrency drainers are not about breaking into wallets; they're about tricking users into approving malicious transactions. BleepingComputer reports that platforms like Lucifer DaaS are...

threat-inteldata-breachmalwarephishingbleepingcomputer
/SCW Research /MEDIUM