Cuffed: Ukraine police collar six Clop ransomware gang suspects in joint raids with South Korean cops
- Reference: 1623850640
- News link: https://www.theregister.co.uk/2021/06/16/clop_ransomware_gang_arrests_ukraine/
- Source link:
"It was established that six defendants carried out attacks of malicious software such as 'ransomware' on the servers of American and [South] Korean companies," alleged Ukraine's national police force in a statement [1]published at lunchtime today.
[2]
Ukrainian Police's stash of seized cash from Clop ransomware gang Pic via: Ukraine police
While the gang is notorious in the West for indiscriminately targeting well-off companies and extorting ransoms in exchange for decryption keys, its most shocking moment was when a poorly secured [3]Accellion file transfer appliance gave the criminals access to defence contractor Bombardier. There the criminals were able to [4]copy blueprints for an airborne early warning radar fitted to the company’s flagship AWACS-style military jet.
The six suspects were arrested in joint raids carried out with South Korean law enforcement authorities earlier today, cops in Ukraine said.
Back in December, Clop had targeted a South Korean retailer, E-Land, [5]reportedly stealing two million credit card details over a 12-month period. Cops in South Korea apparently identified the Clop suspects soon after.
[6]
"Using remote access, the suspects activated malicious software 'Cobalt Strike', which provided information about the vulnerabilities of infected servers for further capture," continued the police statement, adding that the Clop gang had been seen deploying the Flawedammyy remote-access trojan after securing access to the victim's network.
[7]
[8]
John Hultquist, VP of Analysis, Mandiant Threat Intelligence, commented: "The Cl0p operation has been used to disrupt and extort organizations globally in a variety of sectors including telecommunications, pharmaceuticals, oil and gas, aerospace, and technology. The actor FIN11 has been strongly associated with this operation, which has included both ransomware and extortion, but it is unclear if the arrests included FIN11 actors or others who may also be associated with the operation.
"The arrests made by Ukraine are a reminder that the country is a strong partner for the US in the fight against cybercrime and authorities there are making the effort to deny criminals a safe harbor. This is especially relevant as President Biden and Putin discuss the state of cyberthreats emanating from Russia, including the ransomware threat, which has increasingly threatened critical infrastructure and the everyday lives of people around the world."
[9]
A video posted to YouTube by the police in Ukraine showed them seizing large amounts of cash, a white Tesla car, a black Mercedes and towing away other vehicles on trucks.
[10]Youtube Video
In March, the Clop gang [11]cheekily targeted infosec firm Qualys , dumping stolen data online in an apparent extortion attempt. Its steal-leak-ransom methodology was infamous; [12]Trend Micro recently noted that out of the most notorious ransomware gangs (Conti, Doppelpaymer, Egregor, Clop and REvil), Clop led the way, with 5TB of stolen data published online in various places.
[13]
Among Clop's targets this year were various US institutions, with the Ukraine cops naming Stanford University Medical School, the University of Maryland and the University of California. One infosec source mused to The Register that while all three had fallen victim to attacks on outdated Accellion file-transfer appliances (a common attack vector in 2020/early 2021), so far ransomware attacks hadn't been publicly noted against those organisations.
[14]The AN0M fake secure chat app may have been too clever for its own good
[15]After oil giant Shell hit by Clop ransomware gang, workers' visas dumped online as part of extortion attempt
[16]Oh SITA: Airline IT provider confirms passenger data leaked after major 'cyber-attack'
[17]Qualys hit with ransomware: Customer invoices leaked on extortionists' Tor blog
[18]Revealed: The military radar system swiped from aerospace biz, leaked online by Clop ransomware gang
[19]Clop ransomware gang clips sensitive files from Atlantic Records' London ad agency The7stars, dumps them online
[20]Clop ransomware gang leaks online what looks like stolen Bombardier blueprints of GlobalEye radar snoop jet
F-Secure's Mikko Hypponen noted that despite the arrests, Clop's Tor blog – used for posting details of stolen files – was still online.
One note about the Clop arrests in Ukraine today. Their leak site is still up and running in tor hidden service. [21]pic.twitter.com/89T8fSQbJU — @mikko (@mikko) [22]June 16, 2021
Usually when law enforcement scores a takedown of cyber crims, they also replace the targets' website with their own logos. The absence of a takedown page suggests Clop has active members who have control of the gang's web infrastructure.
"A criminal case under Part 2 of Art. 361 (Unauthorized interference in the work of computers, automated systems, computer networks or telecommunications networks) and Part 2 of Art. 209 (Legalization (laundering) of property obtained by criminal means) of the Criminal code of Ukraine. The defendants face up to eight years in prison. Investigative actions continue," concluded the Ukraine police statement. ®
* Also styled as Cl0p
Get our [23]Tech Resources
[1] https://www.npu.gov.ua/news/kiberzlochini/kiberpolicziya-vikrila-xakerske-ugrupovannya-u-rozpovsyudzhenni-virusu-shifruvalnika-ta-nanesenni-inozemnim-kompaniyam-piv-milyarda-dolariv-zbitkiv/
[2] https://regmedia.co.uk/2021/06/16/handout_ukraine_police_cl0p_cash_seizure.jpg
[3] https://www.theregister.com/2021/02/23/bombardier_Cl0p_ransomware_leaks/
[4] https://www.theregister.com/2021/03/29/shell_clop_ransomware_leaks_update/
[5] https://threatpost.com/Cl0p-gang-2m-credit-cards-eland/161833/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMogH1vpv3lbYrYjqrsHugAAAM8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMogH1vpv3lbYrYjqrsHugAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMogH1vpv3lbYrYjqrsHugAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMogH1vpv3lbYrYjqrsHugAAAM8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.youtube.com/watch?v=PqGaZgepNTE
[11] https://www.theregister.com/2021/03/03/qualys_ransomware_Cl0p_gang/
[12] https://www.theregister.com/2021/06/09/trend_micro_nefilim_ransomware_research/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMogH1vpv3lbYrYjqrsHugAAAM8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2021/06/14/an0m_and_yamamoto/
[15] https://www.theregister.com/2021/03/29/shell_clop_ransomware_leaks_update/
[16] https://www.theregister.com/2021/03/05/oh_sita_airline_it_provider/
[17] https://www.theregister.com/2021/03/03/qualys_ransomware_clop_gang/
[18] https://www.theregister.com/2021/02/24/seaspray_radar_ransomware/
[19] https://www.theregister.com/2021/01/22/the7stars_ransomware_attack_clop/
[20] https://www.theregister.com/2021/02/23/bombardier_clop_ransomware_leaks/
[21] https://t.co/89T8fSQbJU
[22] https://twitter.com/mikko/status/1405143822707965958?ref_src=twsrc%5Etfw
[23] https://whitepapers.theregister.com/
Covid profits
The image claims that they would target pharmaceutical companies as they have made a profit form the pandemic, but I thought companies like Astra Zeneca etc. were doing the vaccines at cost, rather than for profit?
As an aside, I just wonder how many cyber crooks in Russia who have attacked Western companies or government organisations have been arrested in Russia. Or indeed, whether any Western cybercriminals have attacked Russian interests and been arrested by the Western police.
Juristiction
Where does a cyber crime take place?
At the keyboard or on a target on the other side of the world?
Its an interesting question.... made more difficult if the source and destination don't have extradition treaties...
Russia in particular has a law making it illegal to extradite any Russian citizen...
Re: Covid profits
AstraZeneca are selling their vaccine at cost during the pandemic, but Pfizer are making billions in profit from selling theirs.
For Pfizer, their COVID-19 vaccine is the majority of their current sales, and they have a high profit margin. They plan on raising prices substantially in future when they are no longer selling directly to national governments but are dealing with health care providers directly, and so can set whatever price they want instead of having to negotiate with big national buyers.
So, if you are planning on targeting a pharmaceutical company, make sure you pick the right one. Some are raking in the cash while others don't have as much financial motivation to pay up.
"whether any Western cybercriminals have attacked Russian"
There are too few valuable targets there - and probably far harder to extract cash from them - even Western cybercriminals probably prefer Western targets - moreover some social engineering techniques would need a knowledge of Russian they don't have.
State-level cyber attacks are another story, and of course police doesn't target them.
So you could say it's a case of...
...Clop clipped?
(I am so very sorry)