European and North American cybercrime investigators said they have dismantled the heart of a malware operation directed by Russian criminals after a global operation involving British, Canadian, Danish, Dutch, French, German and US police.
International arrest warrants have been issued for 20 suspects, most of them living in Russia, by European investigators, while indictments were unsealed in the US against 16 people.
Those charged include the alleged leaders of the Qakbot and Danabot malware operations, including Rustam Rafailevich Gallyamov, 48, who lives in Moscow and Aleksandr Stepanov, 39, AKA JimmBee, and Artem Aleksandrovich Kalinkin, 34, AKA Onix, both of Novosibirsk, Russia, the US Department of Justice said.
Photo: Reuters
Cyberattacks aimed at destabilizing governments or simple theft and blackmail are becoming increasingly pernicious. The high-street retailer Marks & Spencer is one of the most high-profile and recent victims in the UK this month.
The Europeans, led by the German crime agency, Bundeskriminalamt (BKA), released public appeals in their attempts to track down 18 suspects believed to be involved in the Qakbot malware family, along with a third malware known as Trickbot.
BKA and its international counterparts said the majority of the suspects were Russians. The Russian national Vitalii Nikolayevich Kovalev, 36, already wanted in the US, is one of BKA’s most wanted.
He is allegedly behind Conti, considered to be the most professional and best-organized ransomware blackmail group in the world, with Kovalev described as one of the “most successful blackmailers in the history of cybercrime” by German investigators.
Using the pseudonyms Stern and Ben, BKA said that he is claimed to have attacked hundreds of companies worldwide and extracted large ransom payments from them.
Kovolev, 36, from Volgorod, is believed to be living in Moscow, where several firms are registered in his name. He was identified by US investigators in 2023 as having been a member of Trickbot.
Investigators also believe he was at the helm of Conti and other blackmail groups, such as Royal and Blacksuit, founded in 2022. His own cryptowallet is said to be worth about 1 billion euros (US$1.1 billion)
BKA said that of the 37 perpetrators they identified, they had enough evidence to issue 20 arrest warrants.
The US attorney’s office in California unsealed the details of charges against 16 defendants who allegedly “developed and deployed the DanaBot malware.”
The criminal infiltrations into victims’ computers were “controlled and deployed” by a Russia-based cybercrime organization that has infected more than 300,000 computers around the world, particularly in the US, Australia, Poland, India and Italy.
It was advertised on Russian-language criminal forums and also had an “espionage variant used to target military, diplomatic, government and non-governmental organizations,” the indictment says.
“For this variant, separate servers were established, such that data stolen from these victims was ultimately stored in the Russian Federation,” it added.
Young Chinese, many who fear age discrimination in their workplace after turning 35, are increasingly starting “one-person companies” that have artificial intelligence (AI) do most of the work. Smaller start-ups are already in vogue in Silicon Valley and elsewhere, with rapidly advancing AI tools seen as a welcome teammate even as they threaten layoffs at existing firms. More young people in China are subscribing to the model, as cities pledge millions of dollars in funding and rent subsidies for such ventures, in alignment with Beijing’s political goal of “technological self-reliance.” “The one-person company is a product of the AI era,” said Karen Dai
South Korea’s air force yesterday apologized for a 2021 midair collision involving two fighter jets, a day after auditors said the pilots were taking selfies and filming during the flight and held them responsible for the accident. “We sincerely apologize to the public for the concern caused by the accident that occurred in 2021,” an air force spokesman told a news conference, adding that one of the pilots involved had been suspended from flying duties, received severe disciplinary action and has since left the military. The apology followed a report released on Wednesday by the South Korean Board of Audit and Inspection,
About 240 Indians claiming descent from a Biblical tribe landed at Tel Aviv airport on Thursday as part of a government operation to relocate them to Israel. The newcomers passed under a balloon arch in blue and white, the colors of the Israeli flag, as dozens of well-wishers welcomed them with a traditional Jewish song. They were the first “bnei Menashe” (“sons of Manasseh”) to arrive in Israel since the government in November last year announced funding for the immigration of about 6,000 members of the community from the states of Manipur and Mizoram in northeast India. The community claims to descend from
‘TROUBLING’: The firing of Phelan, who was an adviser to a nonprofit that supported the defense of Taiwan, was another example of ‘dysfunction’ under Trump, a US senator said US Secretary of the Navy John Phelan has been fired, a US official and a person familiar with the matter said on Wednesday, in another wartime shakeup at the Pentagon coming just weeks after US Secretary of Defense Pete Hegseth ousted the Army’s top general. The Pentagon announced his departure in a brief statement, saying he was leaving the administration “effective immediately,” but it did not provide a reason or say whether it was his decision to go. The sources, who spoke on condition of anonymity, said Phelan was dismissed in part because he was moving too slowly to implement reforms to