Thursday, June 1, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

U.S., U.K. Governments Sanction Alleged Members of Trickbot Malware Group

Researcher by Researcher
February 9, 2023
in Cybersecurity
0
U.S., U.K. Governments Sanction Alleged Members of Trickbot Malware Group
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


The United States and United Kingdom governments have sanctioned seven Russian nationals who they allege are part of the prolific Trickbot cybercrime group, which has been active for nearly a decade and has been associated with Ryuk and Conti ransomware and has targeted hospitals, schools, government agencies, and other sensitive organizations.

The sanctions from the Department of the Treasury’s Office of Foreign Asset Control and the UK’s Foreign, Commonwealth, and Development Office are the result of a joint, ongoing investigation into the Trickbot group’s activities and are the latest move in the U.S. government’s campaign against cybercrime and ransomware groups. OFAC has sanctioned a number of Russian and Chinese individuals associated with cybercrime and APT activity, and last month the Department of Justice arrested the alleged operator of the Bitzlato cryptocurrency exchange, which authorities say was a major hub for laundering ransomware payments.

The individuals sanctioned by the agencies are Vitaly Kovalev, Maksim Mikhailov, Valentin Karyagin, Mikhail Iskritskiy, Dmitry Pleshevskiy, Ivan Vakhromeyev, and Valery Sedletski. Also on Thursday, the U.S, indicted Kovalev for bank fraud and conspiracy to commit bank fraud. Treasury officials said Thursday that current members of the Trickbot group are associated with Russian intelligence agencies.

“Cyber criminals, particularly those based in Russia, seek to attack critical infrastructure, target U.S. businesses, and exploit the international financial system,” said Treasury Under Secretary Brian Nelson. “The United States is taking action today in partnership with the United Kingdom because international cooperation is key to addressing Russian cybercrime.”

“We are sending a clear signal to them and others involved in ransomware that they will be held to account.”

The Trickbot group, which is also known as Wizard Spider, has been around for about seven years and evolved from an older group that developed and deployed the Dyre trojan. The group is based in Russia and historically has been financially motivated, targeting companies in the U.S., UK, and around the world, with the notable exception of Russia. Though the sanctioned men are all Russians, the ffects of the sanctions could still be tangible for them.

“These are smaller cogs in a larger machine but at the very least it does go to ensuring there are consequences to this sort of activity. It could pose a risk to them or their livelihood even if they don’t make the mistake of leaving their country,” said Jeremy Kennelly, principal, lead analyst at Mandiant-Google Cloud.

While U.S. agencies have imposed sanctions against cybercrime groups and individuals in the past, this is a first for the UK.

“This is a hugely significant moment for the UK and our collaborative efforts with OFAC to disrupt international cyber criminals,” Graeme Biggar, director general of the UK National Crime Agency, said.

“The sanctions are the first of their kind for the UK and signal the continuing campaign targeting those responsible for some of the most sophisticated and damaging ransomware that has impacted the UK and our allies. They show that these criminals and those that support them are not immune to UK action, and this is just one tool we will use to crack down on this threat and protect the public.”

As with many cybercrime operations, the Trickbot group has evolved over time and has been affiliated with a number of other organizations, most notoriously the Conti ransomware group. Conti was among the more audacious and damaging ransomware crews on the board before it shut down operations in mid-2022 after intense investigations from law enforcement and security researchers. Trickbot also is often associated with the Emotet malware and has been known to deliver the Ryuk ransomware and BazarLoader malware, as well.

“t’s complicated but it is in large part a number of closely affilliated groups with social and financial ties. The impression that this is amorphous comes from that set of affiliations,” Kennelly said.

“By sanctioning these cyber criminals, we are sending a clear signal to them and others involved in ransomware that they will be held to account,” UK Foreign Secretary James Cleverly said.



Source link

Related articles

Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023
Tags: AllegedgovernmentsGroupmalwaremembersSanctionTrickbot
Share76Tweet47

Related Posts

Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
0

Threat actors are exploiting a critical-severity Zyxel flaw in order to add vulnerable devices to a Mirai botnet variant. While...

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023
0

Cisco on Wednesday announced that it’s acquiring California-based cybersecurity firm Armorblox for its artificial intelligence (AI) technology. Armorblox specializes in...

8 best practices for securing your Mac from hackers in 2023

8 best practices for securing your Mac from hackers in 2023

June 1, 2023
0

Best practices for securing your Mac against potential hacks and security vulnerabilities include enabling the firewall, using strong passwords and...

ZuoRAT Malware Found Hitting Home Routers

New SeroXen RAT Emerges | Decipher

June 1, 2023
0

Security researchers are tracking a new fileless RAT named SeroXen that has the capability to evade many EDR systems and...

Sentra Raises $30 Million for DSPM Technology

Chrome 114 Released With 18 Security Fixes

May 31, 2023
0

Google this week announced the release of Chrome 114 to the stable channel with a total of 18 security fixes...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
All eyes on APIs: Top 3 API security risks and how to mitigate them

All eyes on APIs: Top 3 API security risks and how to mitigate them

June 1, 2023
Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup /

June 1, 2023

Recent Posts

Spring Framework Flaw Exploited in Mirai Malware Attacks

Threat Actors Exploit Critical Zyxel Flaw in Botnet Attacks

June 1, 2023
All eyes on APIs: Top 3 API security risks and how to mitigate them

All eyes on APIs: Top 3 API security risks and how to mitigate them

June 1, 2023
Cisco Acquiring Armorblox for Predictive and Generative AI Technology

Cisco Acquiring Armorblox for Predictive and Generative AI Technology

June 1, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved