MalwareTips News KillSec ransomware servers and leak site seized in international crackdown

Security News
0 Replies 96 Views

Which safeguard against this type of ransomware attack have you already put in place?

  • Multi-factor authentication

    Votes: 0 0.0%
  • Offline or unchangeable backups

    Votes: 1 50.0%
  • Checks for exposed cloud storage

    Votes: 0 0.0%
  • More than one of these

    Votes: 1 50.0%
  • I am not sure

    Votes: 0 0.0%

  • Total voters
    2

News Now

Happening Now
Verified
MalwareTips-news-151.jpg

Image: Group-IB

Police have seized KillSec’s leak site and core servers, while three suspects were provisionally arrested in an international operation. The group targeted organizations worldwide, particularly in financial services and healthcare, putting business and patient data at risk.

What Operation KillSwitch achieved​

Group-IB, which provided intelligence to Operation KillSwitch, says investigators identified a 16-year-old as KillSec’s suspected main operator. Authorities also searched eight properties across Greece, Romania, Spain and the United Kingdom.

Police took control of five central servers and redirected KillSec’s domains to a seizure notice. At least 110TB of stolen data was secured, although examining that evidence may change the current estimate of about 500 successful attacks.

Who KillSec targeted​

KillSec operated a ransomware-as-a-service scheme, supplying attack tools to affiliates in return for part of each ransom. Investigators linked it to around 1,000 suspected attacks worldwide.

Group-IB found 274 organizations publicly named on KillSec’s leak site. About 35% were in the United States and 17% in India, with financial services and healthcare the most affected sectors.

Victims did not always have their files encrypted. KillSec also sold stolen information directly, reportedly asking from $5,000 for one company’s records up to $500,000 for data allegedly taken from a global insurer.

Reduce exposure to similar attacks​

KillSec affiliates reportedly used phishing, password-guessing attacks against exposed Remote Desktop Protocol services, and known flaws in internet-facing software. Some claimed victims suffered no network break-in because their cloud storage had mistakenly been left public.

  • Turn on multi-factor authentication for remote access, so a password alone is not enough to sign in.
  • Inventory internet-facing systems, including remote access services and cloud storage, and check that storage is not publicly accessible.
  • Prioritize fixes for vulnerabilities known to be actively exploited.
  • Keep offline, unchangeable backups and protect virtualization platforms as critical systems.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

You may also like...

Continue exploring the conversation.

Back
Top