Arab Press

بالشعب و للشعب
Saturday, Feb 22, 2025

US Seizes $6.1 Million In Relation To Russian Ransomware Operator

US Seizes $6.1 Million In Relation To Russian Ransomware Operator

U.S. Attorney General Merrick Garland, speaking at a news conference, said another alleged ransomware attacker, Ukrainian Yaroslav Vasinskyi, has been arrested in Poland, and the United States has requested extradition.
The U.S. Justice Department charged a Ukraine national and a Russian in one of the worst ransomware attacks against American targets, court filings showed on Monday.

The latest U.S. actions follow a slew of measures taken to combat a surge in ransomware that has struck several big companies, including an attack on the largest fuel pipeline in the United States that crippled fuel delivery for several days.

An indictment accused Ukrainian Yaroslav Vasinskyi, who was arrested in Poland last month, of breaking into Florida software provider Kaseya over the July 4 weekend.

From there, he and accomplices simultaneously distributed REvil ransomware to as many as 1,500 Kaseya customers, encrypting their data and forcing some to shut down for days, it said.

Vasinskyi is charged with breaking into the victim companies and installing encryption software, developed by the core REvil group. REvil directly handled the ransom negotiations and split the profits with affiliates like Vasinskyi. This model allowed the notorious ransomware gang to extort numerous companies for cryptocurrency.

Kimberly Goody, director of financial crime analysis at security company Mandiant, said targeting affiliates could be more effective than going after the core gangs, because their skills are more prized than encryption software, which is ubiquitous. Some affiliates also work with multiple gangs.

The arrest was part of a major ongoing sweep against key ransomware figures coordinated by the FBI, Europol and national police organizations throughout Europe, with help from private security companies.

REvil, also involved in an attack against top global meatpacker JBS SA, was penetrated by the joint operation, Reuters reported previously, and authorities recovered $6 million in ransom payments.

REvil announced it was shutting down last month, as did a rival gang involved in the hack of Colonial Pipeline.

Vasinskyi and another alleged REvil operative, Russian national Yevgeniy Polyanin, were charged in U.S. District Court for the Northern District of Texas with conspiracy to commit fraud and conspiracy to commit money laundering, among other offenses.

The Treasury Department said the two face sanctions for their role in ransomware incidents in the United States, as well as a virtual currency exchange called Chatex "for facilitating financial transactions for ransomware actors."

Latvian and Estonian government agencies were vital to the investigation, the Treasury said.

"International partnerships can disrupt bad actors," former U.S. civilian cyber defense Chris Krebs said on Twitter.

Deputy Attorney General Lisa Monaco credited Kaseya for its help in the investigation. "We are here today because in their darkest hour, Kaseya made the right choice and they decided to work with the FBI... in doing so, we were able to identify and help many victims of this attack."

The Treasury said more than $200 million in ransom payments were paid in Bitcoin and Monero.

Vasinskyi, 22, was being held in Poland pending U.S. extradition proceedings, while Polyanin, 28, remains at large. Russia's tolerance of major gangs targeting U.S. critical industry has been a flashpoint in relations with the Biden administration.

President Joe Biden said on Monday that his administration has taken "important steps to harden" critical U.S. infrastructure against cyberattacks. "When I met with President Putin in June, I made clear that the United States would take action to hold cybercriminals accountable. That's what we have done today", he said in a statement released by the White House.

Although discussions continue, security experts and most U.S. officials said they had not seen an overall decrease in ransomware attacks. Encryption software used for such attacks is freely available.

Reuters could not reach legal representatives for the two men accused on Monday, and no attorneys for them were listed in court filings.

The indictment said the Ukrainian hacker and other conspirators started deploying hacking software around April 2019 and regularly updated and refined it. It said he also laundered money obtained through the extortion scheme.

Europol said earlier on Monday that Romanian authorities on Nov. 4 arrested two other individuals suspected of attacks deploying the REvil ransomware. Officials in South Korea previously arrested three more people associated with REvil and two related strains of ransomeware, Europol added.

Twelve suspects believed to have mounted ransomware attacks against companies or infrastructure in 71 countries were "targeted" in raids in Ukraine and Switzerland, Europol said on Friday.
Newsletter

Related Articles

Arab Press
0:00
0:00
Close
The negotiation teams of Trump and Putin meet directly, establishing the groundwork for a significant advance.
Israeli Minister Urges Hamas to Surrender and Depart from Gaza.
Iran Considers Moving Its Capital Due to Urban Difficulties
Israel and Hamas Finalize Sixth Exchange of Hostages and Prisoners During Continuing Gaza Ceasefire
Leaders of BRICS to Gather in Rio de Janeiro for July Summit
Muhsin Hendricks, a trailblazing openly gay imam, was killed in South Africa.
Trump's special envoy for hostage affairs cautions Hamas against challenging Trump before Saturday's deadline.
Two British citizens apprehended in Iran amid escalating tensions.
Israel Issues Threat of Military Action as Hostage Negotiations with Hamas Continue
Hamas Coordinates Worldwide Solidarity Marches in Reaction to U.S. and Israeli Initiative
Israel Warns of Ending Gaza Ceasefire Due to Hostage Situation
King Abdullah II Dismisses US Proposal to Relocate Palestinians, Commits to Welcoming Gaza Children.
Lebanon Installs New Government with Hezbollah's Impact on Key Ministries
Report: Iran Attempted to Assassinate Trump During Election Campaign
U.S. Authorizes $7.4 Billion Arms Sale to Israel
Iran's Supreme Leader Rejects Nuclear Negotiations with the U.S.
UN Chief Denounces Trump's Gaza Plan, Cautions Against Ethnic Cleansing
Pressure Intensifies for a Free Trade Agreement between the UK and GCC in Light of Economic Difficulties
Israel to Withdraw from UN Human Rights Council Due to Accusations of Anti-Semitism
EU Reaffirms Gaza's Essential Role in Future Palestinian State Following Trump's Proposal
Iranian Currency Reaches All-Time Low Amid US 'Maximum Pressure' Initiative.
UN Reaffirms Ban on Deportation from Occupied Territories Amid US Gaza Proposal
Palestinians Fear Repeat of 'Nakba' Amid Ongoing Crisis in Gaza
UAE Aids in the Exchange of 300 Prisoners Between Russia and Ukraine
Egypt Seeks Global Backing for Two-State Solution Following US Proposal for Gaza Plan
Trump's Suggestion to 'Seize Control' of Gaza Represents a Significant Shift in US Policy
French President is the first EU leader to extend congratulations to the new Syrian President.
Tunisian President Appoints New Finance Minister Amid Economic Crisis
Trump Suggests U.S. 'Takeover' of Gaza, Prompting Global Worries
Trump's Proposal for Gaza Provokes Global Debate
President Trump Suggests Moving Gaza's Palestinian Population
Aga Khan IV, Spiritual Leader and Philanthropist, Dies at 88
Erdogan and Syria's Sharaa Talk About Collaboration to Counter Kurdish Militants
Trump Suggests U.S. Control of Gaza Strip Amid Ongoing Conflict
Trump Resumes 'Maximum Pressure' Strategy to Limit Iran's Oil Exports.
Ex-British Soldier Sentenced for Espionage on Behalf of Iran and Fleeing from Prison
Gazans in Egypt Reject Displacement, Struggle with Return to War-Torn Home
Queen Rania Urges Protection of Children’s Rights at Vatican Summit
Hamas Officials Ready to Begin Negotiations for Phase Two of Gaza Truce
Trump Expresses Caution Over Gaza Ceasefire as Netanyahu Visits Washington
Oman to Host 18th Indian Ocean Conference on Maritime Security and Trade
Emir of Kuwait Meets BlackRock CEO for Talks on Investment Opportunities
Queen Rania of Jordan Calls for Global Action on Children’s Rights at Vatican Summit
Egyptian President El-Sisi Invited for White House Meeting Following Jordanian King’s Visit
Queen Rania Calls for Protection of Children’s Rights at Vatican Summit
Israeli Military Operations Continue on Lebanon Border Amid Ceasefire Tensions
Israeli Hostage's Release Highlights Uncertainty Over Family's Fate
Israeli Military Operations Escalate in Southern Lebanon Amid Hezbollah Tensions
Zayed Award for Human Fraternity Announces 2025 Honorees
Kuwait Anticipates a 12% Increase in Budget Deficit for the 2025-2026 Fiscal Year
×