An international law enforcement operation known as "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, resulting in three arrests and identifying a 16-year-old as the group's alleged administrator.Combined efforts in finding suspectsEuropol and Eurojust, as well as cybersecurity companies Bitdefender and Group-IB, all contributed to the investigation."The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide," according to Europol."Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds,” Europe stated.About the investigation The inquiry started last year and assisted officials in finding suspects like negotiator, administrator, and associate of the cybercrime gang.As per Europol, the suspected main operator and administrator of KillSec is 16 years old. Officials have also discovered members suspected of being an affiliate and a negotiator.KillSec, also known as Kill Security or k1llsec, has reportedly been active since around 2024 and operated as a ransomware-as-a-service (RaaS) group. About the attack Investigators say the attackers gained access to organizations by exploiting software vulnerabilities and poorly secured access points, including systems associated with cloud storage.After gaining access, the attackers allegedly stole sensitive corporate information and transferred it to infrastructure controlled by the group. They then used a dark-web leak site to pressure victims into paying ransom. Victims were threatened with the public release of stolen information if they refused to pay.The impact Investigators have linked KillSec to approximately 1,000 suspected attacks worldwide, with around 500 currently identified as successful. Authorities stressed that these figures could change as they continue examining seized computers, servers and other evidence. At least 70 suspected attacks involved organizations in Germany, including 18 connected to Hamburg. Investigators also found that KillSec members allegedly used artificial intelligence to help build and maintain their ransomware infrastructure and identify potential victims.By taking control of KillSec’s leak site and servers, authorities have prevented the group from continuing to use that infrastructure to publish stolen information. However, the seizure cannot necessarily remove copies of information that may already have been obtained by criminals or downloaded by others.The investigation may also identify additional victims, attacks and individuals involved in the operation.Authorities are now analyzing the seized evidence and tracing alleged criminal proceeds, including cryptocurrency.
Read the original article:
