BTC $86,707.13 +3.47%
ETH $2,749.10 +1.74%
BNB $778.55 +1.16%
XRP $1.54 +3.66%
SOL $122.21 +4.03%
TRX $0.3350 +0.66%
DOGE $0.0971 +2.72%
ADA $0.2569 +3.64%
BCH $315.04 +1.88%
LINK $14.41 +0.08%
HYPE $90.95 +1.67%
AAVE $182.98 +11.57%
SUI $1.18 +1.79%
XLM $0.2251 +1.49%
ZEC $1,380.46 -1.60%
AAPL $332.19 +0.17%
AMZN $251.36 -0.03%
GOOGL $341.54 -2.35%
MSFT $518.65 -0.11%
META $732.07 +0.57%
NVDA $235.90 +2.48%
TSLA $357.40 +0.15%
SNDK $1,777.86 +1.81%
INTC $123.83 +3.79%
SPCX $149.74 -0.95%
MU $1,107.70 +5.03%
AMD $632.89 +3.25%
BTC $86,707.13 +3.47%
ETH $2,749.10 +1.74%
BNB $778.55 +1.16%
XRP $1.54 +3.66%
SOL $122.21 +4.03%
TRX $0.3350 +0.66%
DOGE $0.0971 +2.72%
ADA $0.2569 +3.64%
BCH $315.04 +1.88%
LINK $14.41 +0.08%
HYPE $90.95 +1.67%
AAVE $182.98 +11.57%
SUI $1.18 +1.79%
XLM $0.2251 +1.49%
ZEC $1,380.46 -1.60%
AAPL $332.19 +0.17%
AMZN $251.36 -0.03%
GOOGL $341.54 -2.35%
MSFT $518.65 -0.11%
META $732.07 +0.57%
NVDA $235.90 +2.48%
TSLA $357.40 +0.15%
SNDK $1,777.86 +1.81%
INTC $123.83 +3.79%
SPCX $149.74 -0.95%
MU $1,107.70 +5.03%
AMD $632.89 +3.25%

ransomware

All
Article
Flash

first_img Spanish police arrested a 16-year-old boy involved in operating the KillSec ransomware group

According to Decrypt, the European Union's law enforcement agency reported that Spanish police arrested a 16-year-old Romanian suspect in Alicante, suspected of being an administrator and main operator of the ransomware group KillSec.Two other suspects in their twenties were arrested in the UK and Romania, respectively; another developer who just turned 18 in August this year has been identified but has not been arrested due to some crimes occurring during their minor years.This operation, codenamed Operation KillSwitch, was led by the Hamburg State Criminal Police and the city's prosecution office, focusing on approximately 1,000 suspected attacks worldwide, with about 500 confirmed as successful intrusions.Law enforcement searched eight locations in Spain, Greece, Romania, and the UK, seized five central servers, and redirected related domain names to seizure announcement pages, while also confiscating at least 110 TB of stolen data.KillSec has been active since around 2024, exploiting software vulnerabilities and poorly secured cloud storage entry points to infiltrate corporate systems, copying internal data and naming victim organizations on dark web leak sites, threatening to publicly release documents to demand cryptocurrency ransoms, and if the target refuses to pay, they release the data for free.The Swiss Federal Police noted that the group also employed double extortion tactics, first encrypting servers and then applying pressure. U.S. prosecutors' charges indicate that a Dutch national residing in the UK, Fouad Eltibrizi (nicknamed Archduke), was indicted by a federal grand jury in Puerto Rico on September 16, subsequently arrested, and awaiting extradition, facing up to 10 years in prison. The European Cybercrime Centre, under the European Union Agency for Law Enforcement Cooperation, is assisting in tracing cryptocurrency funds and conducting digital forensics.

The EU sanctions "the most active ransomware operator in history" Stern, involved in over 300 million dollars in ransom inflow

The United States, the European Union, and the United Kingdom jointly announced sanctions against a group involving state-level hacker organizations, cybercrime gangs, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global businesses, critical infrastructure, and government agencies. Among the most notable is the EU's sanction against the Russian cybercriminal Vitaly Nikolayevich Kovalev (alias "Stern").The EU has identified Stern as one of the core managers of the notorious Trickbot Group ransomware organization, which includes several high-risk ransomware variants such as Conti ransomware and Ryuk. On-chain analysis shows that wallet addresses associated with Stern have received over $300 million in ransom payments, potentially making him the "largest confirmed ransomware operator" to date. According to analysis, the $300 million only represents the profits obtained by Stern personally, and the overall illegal income of the Trickbot group may be much higher.On-chain fund flows indicate that Stern has had transactional connections with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum. Investigations show that Stern plays a role similar to "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning.

ZachXBT accuses Russian OTC broker Aleks Khinkis of being involved in a $4.7 million ransomware money laundering case

Renowned on-chain investigator ZachXBT released a report today stating that a Russian over-the-counter (OTC) broker named Aleksandr (Aleks) Khinkis is suspected of assisting ransomware groups in laundering over $4.7 million since 2025 through a single cryptocurrency trading platform account.The related funds involve three suspicious ransom payments, totaling approximately 796 bitcoins (BTC). The investigation shows that these funds were transferred in batches to his trading platform's deposit address (0xa756) after being bridged between Bitcoin and Avalanche, completing a total of 75 transactions from 2025 to 2026. Additionally, approximately $16.6 million is currently still held in Aave and is being gradually liquidated.ZachXBT pointed out multiple ransom transactions: a ransom payment of about 72 BTC in September 2025 was bridged to the related address; a ransom of about 164 BTC was also discovered in October 2025 and converted to approximately $3.8 million. Some related addresses were blacklisted by Tether in November 2025, and the subsequently frozen USDT was destroyed three weeks ago, indicating that law enforcement and compliance agencies have intervened.Earlier in 2023, this account was also involved in a ransom transaction of about 560 BTC, which was circulated through multiple intermediary addresses and trading platforms before being bridged back to the Avalanche network in 2024. Furthermore, the investigation pointed out that the source addresses of the related bitcoins have a high correlation with multiple ransomware addresses, suspected of serving as payment transit nodes. Although some funds remain dormant, ZachXBT warned that they may still be laundered in the future and urged victims to report related addresses promptly to freeze the funds.
app_icon
ChainCatcher Building the Web3 world with innovations.