Showing posts with label Europol. Show all posts
Showing posts with label Europol. Show all posts

Wednesday, 28 February 2018

Decrypting Tool For GandCrab Ransomware Available



Victims of the GandCrab ransomware can regain access to their encrypted files. The decrypting tool for GandCrab was made available today on the site nomoreransom.org by the Romanian police in cooperation with Bitdefender and the European police organization Europol.

GandCrab has been observed in the wild for about a month and has now made more than 50,000 victims worldwide, including many Europeans. It is therefore one of the most aggressive forms of ransomware this year, according to Europol .

GandCrab spreads via manipulated advertisements on websites and via fake invoices that are sent as attachments by e-mail. When the malware is installed, the files on the victim's computer are encrypted and an amount of 300 to 500 dollars in ransom is demanded, to be paid in the virtual currency DASH.

As far as we know, GandCrab is the first ransomware copy that requires payment in DASH. GandCrab also has an affiliate program where the ransomware is offered as a service (ransomware-as-a-service) and the developers receive a commission for each ransom payment received.

Tuesday, 10 November 2015

Trend Micro: Only Arrests Can Stop Cyber Crime


Only arrests can really put an end to cyber crime, according to anti-virus firm Trend Micro in response to recent occurrence of various police forces against the Dridex botnet. The FBI, the British National Crime Agency (NCA) and Europol were able to disable several servers of the botnet.

The botnet was used by criminals to steal money from online bank accounts. Despite the occurrence Dridex is still active. "It was developed as a botnet as a service (BaaS). It consists of several botnets each having different configuration files," says Michael Marcos. Although Dridex is affected by the operation of law enforcement agencies were not all servers off.

It was also arrested only one member of the gang Dridex, a system administrator. The other members are still on the run and continued their activities. According to Trend Micro disrupt such operations cyber criminal activities in the short term, but long-term success is not always guaranteed. "They ensure that the least effective threats are removed and cyber criminals can learn from their mistakes. Arrests are therefore required to really put an end to cyber crime," said the virus fighter.

Friday, 6 November 2015

133 People Arrested In Major Action Against Ticket Fraud


At an international operation against ticket fraud, coordinated by the European Cyber ​​Crime Centre (EC3) in The Hague and Ameripol in Bogota, 133 people were arrested. The campaign focused on criminals who buy over the Internet using stolen or forged credit card data airfare.

According to Europol, millions of people are victims of credit card fraud. During the "Global Airport Action Day" worked airlines, online travel agencies and credit card companies along with investigative services from 32 countries to identify suspicious transactions ticket. Subsequently investigative agencies warned that were ready to move several airports. A total of 162 reported suspicious transactions, which ultimately led to 133 arrests.

Wednesday, 14 October 2015

FBI And Europol Disrupt Botnet Digital Bank Robbers


The FBI, the British National Crime Agency (NCA) and Europol are working to disrupt a botnet that criminals use to steal 30 million online bank accounts. It involves the Dridex-malware, where the US government yesterday for warned.

Through the malware managed to infect criminals in Moldova and other countries, computers and then steal data for Internet banking. In this way could then money from online accounts are stolen. One of the managers of the Dridex botnet has now sued. It is a 30 year old man from Moldova who in late August was arrested in Cyprus.

The various investigative agencies are now working for the malware to 'sink holes' so that the criminals behind the botnet can no longer control the infected computers. This involves a continuous campaign directed against different versions of Dridex and the criminals behind it, says Europol.

Monday, 5 October 2015

Interpol And Europol Launch Task Force Against Cyber Crime


Interpol and Europol will together launch a task force to improve the international fight against cyber crime and where law enforcement agencies from other countries can join. There will also be an alliance against abuse of digital currency to be set up by criminals.

These are two of the results of the Europol INTERPOL Cyber Crime Conference, which took place last week in The Hague.The Joint Cooperation & Compatibility Cyber Crime Taskforce Europol and Interpol will create a compatibility list to harmonize the different legal systems and codes for data requests. This should improve cooperation between different law enforcement agencies.

There will also be an alliance against abuse of digital currency for criminal transactions and money laundering. Particular attention was focused on policy, boosting operational cooperation and developing and providing training to combat the criminal use of digital currency. For example, law enforcement agencies empowered to detect digital currency of criminals, seize and confiscate.

Thursday, 6 August 2015

Gang Stealing An Estimated $ 100 Million Of Accounts


A large group of more than 50 cyber criminals stole recent years to an estimated $ 100 million of bank accounts and between 20 and 30 terabytes of data captured. The FBI and security Crowd Strike and Fox-IT today announced at the Black Hat conference in Las Vegas announced.

The gang used the Game Over Zeus malware, a Trojan horse that was on the infamous Zeus Trojan based and was mainly used to steal data from online banking and other services. Game Over Zeus botnet was last June by the FBI, Europol, several companies and police forces from the extracted air . Early this year, the FBI put $ 3 million on the head of a Russian man suspected of developing Game Over Zeus.

Today published data show that the botnet from an average of about 200,000 systems existed. Besides also steal money from bank accounts, the gang held behind Game Over Zeus engaged in espionage in Eastern European countries. In total, there would be via the malware 20 to 30 terabytes of data have been stolen. It also appears from the investigation of the criminals that they are well organized. The gang calls itself the "business club" and consists of more than 50 people. The Russian man who is wanted by the FBI was always seen as a mastermind Game Over Zeus, but he would not be the sole leader of the group of criminals. According to the researchers, there is someone else with whom he leads the gang together.

Tuesday, 3 March 2015

Anti-virus company: Europol Operation Failed Against Botnet


The operation against the Ramnit botnet that Europol several European investigative services and security last week performed partly failed, causing hundreds of thousands of computers controlled by cybercriminals, according to the Russian anti-virus company Doctor Web.

In the operation were seized hundreds of domains that the botnet used to communicate with infected computers, as well as different servers. The Ramnit malware did over a period of almost five years in total to infect 3.2 million computers. The last half year were approximately 500,000 computers have been infected with the malware.

Doctor Web suggests that there are several variations of Ramnit are active, including one which since September 2011 has been announced. This version can steal all kinds of passwords and FTP programs would have on hundreds of thousands of computers are active every day. "Despite the message in the media about a successful operation against the Ramnit botnet, our analysts have no decrease seen botnets that monitors the anti-virus laboratory," the anti-virus company.

According to researchers from the virus fighter would definitely twelve Ramnit botnets operate. Two of these botnets exist together from more than 500,000 infected computers. "The figures show that the parties behind the operation to destroy the botnet Ramnit evidently not been able to turn off all servers of this botnet," as the researchers conclude whatsoever.

Thursday, 26 February 2015

Virus Switched On Millions Of PCs From Windows Update


The Ramnit botnet that this week by Europol, investigative services, Microsoft and security from the air was removed the last 5 years more than 3 million computers Windows Update, Windows Firewall, Windows Defender, User Account Control and the virus off, leaving the machines did not receive important updates and risked getting infected by even more malware.

Ramnit first appeared in 2010. The malware is designed to steal passwords and data for Internet banking. Also, .exe virus, .dll- and .html files on hard drives and connected storage devices infect. Once activated switches the kinds of security measures in Windows as well as the present virus. Ramnit above used a special blacklist with more than 300 different anti-virus programs.

The last time the virus would only disable Microsoft virus scanners. The software giant detected the last six months, some 500,000 computers were infected with Ramnit. Since this week the cyber criminals behind the botnet would no longer be able to communicate with the infected computers. The infection and custom settings are still active.

Virus scanning and removal tools could, however, detect and remove malware. Microsoft recommends that users, therefore, to perform a virus scan regularly. In addition, it is recommended to be careful when opening emails and messages on social media from unknown users and software only download from the website of the supplier. In this way, new infections can be prevented.

Hashes:
b87dda7ab5ff13248e3c084c63d02b4a
4390dec38fefb2f7197b6b5cd3f7ab30
69412c0433d966b49795fa10bb7387ed
72609754b056fe8793fb848fe0167112

Wednesday, 25 February 2015

Large Botnet Achieved By Europol In The Air


Europol has partnered with European investigation services a large botnet off the air that had infected 3.2 million computers worldwide. It involves Ramnit botnet that for years was active and on infected computers include passwords booty made ​​and other data.

Computers were infected by opening links in spam emails and visiting infected websites. Ramnit is also a so-called "file infector" who .exe, .dll- and .html files on hard drives and connected storage devices infected. Once a computer became infected malware added the infected code in these files, and as soon as they were started spreading the infection further. Also were found public FTP servers that were used for distributing Ramnit.

In addition to investigative agencies from the Netherlands, Italy, Germany and Britain Europol coordinated the operation with Microsoft, Symantec and Anubis Networks . During the operation of the botnet Command & Control servers were turned off, and the 300 domains that were used to control infected computers.

"This successful operation demonstrates the importance of cooperation between international investigative agencies and private industry in combating cybercrime. We will remain committed to disable botnets and disrupting the infrastructure used by criminals for cyber crime," said Wil van Gemert, Deputy Director of Europol. Microsoft and Symantec have now been delivered solutions to remove the malware from infected computers.