Connect with us

Hi, what are you looking for?


Operation Cyclone deals blow to Clop ransomware operation

Man in handcuffs

A thirty-month international law enforcement operation codenamed ‘Operation Cyclone’ targeted the Clop ransomware gang, leading to the previously reported arrests of six members in Ukraine.

In June, BleepingComputer reported that Ukrainian law enforcement arrested members of the Clop ransomware gang involved in laundering ransom payments.

This Friday, new information came to light regarding how the operation was conducted and the law enforcement agencies involved.

Interpol’s Operation Cyclone

The transcontinental operation named ‘Operation Cyclone’ was coordinated from INTERPOL’s Cyber Fusion Centre in Singapore, with assistance from Ukrainian and US law enforcement authorities.

This operation targeted Clop for its numerous attacks against Korean companies and US academic institutions, where the threat actors encrypted devices and extorted organizations to pay a ransom or have their stolen data leaked.

In December 2020, Clop conducted a massive ransomware attack against E-Land Retail, a South Korean conglomerate, and retail giant, causing 23 out of 50 NC Department Store and NewCore Outlet retail stores to temporarily close. They later claimed to have stolen 2,000,000 credit cards from the company using point-of-sale malware.

More recently, Clop used a vulnerability in the Accellion secure file transfer gateway to steal confidential and private files of corporations and universities. When $10 million+ ransom demands were not paid, the threat actors publicly released students’ personal information from numerous universities and colleges.

Advertisement. Scroll to continue reading.
Clop ransom note used in Accellion extortion demands
Clop ransom note used in Accellion extortion demands

The US education institutions targeted in the Accellion attacks included the University of Colorado, University of Miami, Stanford Medicine, University of Maryland Baltimore (UMB), and the University of California.

Through intelligence sharing between law enforcement agencies and private partners, Operation Cyclone led to the arrest of six suspects in Ukraine, the search of more than 20 houses, businesses, and vehicles, and the seizure of computers and $185,000 in cash assets.

The operation was also assisted by private partners, including Trend Micro, CDI, Kaspersky Lab, Palo Alto Networks, Fortinet, and Group-IB.

“Despite spiralling global ransomware attacks, this police-private sector coalition saw one of global law enforcement’s first online criminal gang arrests, which sends a powerful message to ransomware criminals, that no matter where they hide in cyberspace, we will pursue them relentlessly,” said INTERPOL’s Director of Cybercrime Craig Jones in an announcement.

US cybersecurity firm Intel 471 previously told BleepingComputer that while the arrested members are linked to the Clop ransomware gang, they were primarily involved in the money laundering for the criminal organization. The intelligence firm further said that core members of the Clop operation are likely out of harm’s way in Russia.

If convicted, the six suspected Clop members face up to eight years in prison.

A video released by Ukraine’s SSU shows investigators conducting raids on the suspect’s property and the seizure of evidence.

Targeting ransomware operations

With ransomware attacks escalating against critical infrastructure, healthcare, businesses, and educational institutions, law enforcement has been applying significant pressure on criminal operations this year.

This law enforcement activity has led to numerous arrests and infrastructure takedowns, including:

Advertisement. Scroll to continue reading.

Law enforcement operations have also led to ransomware gang’s shutting down their operations as they feel law enforcement tightening on their activities.

This includes the recent shutdown of the REvil and BlackMatter operations, as well as Avaddon ransomware’s shutdown in June.

While ransomware gangs may shut down their operations, it does not mean that law enforcement has given up on bringing them to justice.

This week, the US Department of State announced a $10 million reward for identifying or locating key leaders in the DarkSide/BlackMatter ransomware operation.

Thanks to Douglas Mun for the tip!

Source link

Click to comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.




A thirty-month international law enforcement operation codenamed ‘Operation Cyclone’ targeted the Clop ransomware gang, leading to the previously reported arrests of six members in...

Loan And Finance

Official statement from the Labour Party Notification of data incident: We wish to inform you that a third party that handles data on our...

Top Stories

Bitcoin (BTC) starts a new week on a high in more ways than one as BTC/USD seals its highest ever weekly close. After days...

Online Business Success

OUTSOURCE LIFE STEVE WASTERVAL Solopreneurs and small business owners are often crunched for time. Like it or not, you can’t (and probably shouldn’t) try...


If you want to be effective while taking down opponents and gym leaders in Pokémon Brilliant Diamond and Shining Pearl, then you really need...

Top Stories

Neal Stephenson, a popular sci-fi writer coined the phrase “metaverse” in his first best-selling and breakthrough 1992 novel, Snow Crash. Now that concept is...

Loan And Finance

Challenger maintains confident outlook for FY22 1 November 2021 Investment management firm Challenger says it expects to continue performing well, after the business began...

Online Business Success

Entrepreneurship is at the heart of the American spirit, and yet the numbers tell a story of decline since the 1980s. According to the...


You May Also Like

SEO Guide

Want to rank in Google image search? Images that you use as a featured images when writing a post actually appear on Google Images...


Sonos is one of the most popular wireless speaker brands in the world, and for good reason – its range of portable Bluetooth speakers,...


In this post, I will discuss the top ten profitable blogging niches ideas for Adsense approval and high traffic. whether you use Blogger or...

Online Business Success

File photo The Economist Intelligence Unit (EIU) has said that inflation will remain high in Pakistan for the next six months and the rupee...