DoppelPaymer Hackers Caught

With the help of the FBI, German and Ukrainian police recently searched the properties of two suspected members of a global cyber crime gang that has cost victims tens of millions of dollars. 

Police conducted simultaneous raids in Germany and Ukraine last month, seizing evidence and detaining several suspects. Working with law enforcement partners the police in Düsseldorf were able to apprehend eleven people linked to a group that has operated in various aliases since 2010. 

The gang behind the ransomware, known as DoppelPaymer, appears tied to Evil Corp, a Russia-based syndicate engaged in online bank theft well before ransomware became a global phenomenon.

Criminals mostly based in Russia divide into networks and steal sensitive information before activating malware that encrypts data. The criminals demand payment in exchange for decryption keys and a promise not to dump the stolen data online. Amongst its most prominent exploits are thought to be those against both the British and the Irish health services.

In 2020, a woman who needed urgent help died after she had to be taken to another city for treatment after Duesseldorf University Hospital's computers were infected with DoppelPaymer malware.

Ransomware is the world’s most disruptive cyber crime. Gangs mostly based in Russia break into networks and steal sensitive information before activating malware that scrambles data. The criminals demand payment in exchange for decryption keys and a promise not to dump the stolen data online. 

In a 2020 alert, the FBI said DoppelPaymer had been used since late 2019 to target critical industries worldwide including healthcare, emergency services and education, with six- and seven-figure ransoms routinely demanded.
DoppelPaymer has published data stolen from about 200 companies, including in the US defense sector, which resisted payment. Brett Callow, an analyst with the cyber security firm Emsisoft, noted DoppelPaymer’s suspected connection through Evil Corp to the Russian FSB spy agency, “the bust could provide law enforcement with some exceptionally valuable intel,” he said.

Europol said victims in the United States paid out at least 40 million euros ($42.5 million) to the gang between May 2019 and March 2021 to release important data that was electronically locked using the malware.

The chief of the cyber crime department of the North Rhine-Westphalia state police, Dirk Kunze, said that at least 601 victims have been identified worldwide, including 37 in Germany.  The group specialised in “big game hunting,” said Kunze, and ran a professional recruitment operation, recruiting new members with the promise of paid vacation and asking applicants to submit references for past cyber crimes.

Three other suspects couldn’t be arrested as they are beyond the reach of Europol and German police identified the fugitives as Russian citizens, Igor Turashev, 41, and Irina Zemlyanikina, 36, and 31-year-old Igor Garshin, who was born in Russia but whose nationality wasn’t immediately known.

Turashev has been wanted by the FBI since late 2019 in connection with cyber attacks carried out using a predecessor to DoppelPaymer, known as BitPaymer, also linked to Evil Corp. The US has offered a $5 million reward in 2019 for information leading to the capture of the group’s leader, Maxim Yakubets.   

KSLA:    Trend Micro:   Malpedia:     Fox34:    KCTV5:    Independent:     CNN:    ABC:     Security Week:

Image: Unsplash / Behnam Norouzi

You Might Also Read:

Ransomware Gang Makes $100 Million:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« A 'Golden Pipeline' To Secure The Supply Chain
British Cyber Security - New Threats Call For Action »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Venafi

Venafi

Venafi is a world-class cyber-security company dedicated to protecting machine identities for our hyper-connected digital economy.

Miller Group

Miller Group

Miller Group is an IT managed service provider. We proactively monitor and manage your entire business computer network. Services include backup & recovery and cyber security.

Telia Cygate

Telia Cygate

Cygate are specialists in information security, data networks, and data centre and cloud technologies.

DG Technology

DG Technology

DG Technology is a customer-centric technology expert and business consultant that delivers services and products to minimize your information security, compliance, and business risks.

Fluency Security

Fluency Security

Fluency is the only Security Analytics & Orchestration (SAO) solution that automates correlation, detection, validation and ongoing tracking.

Evidence Talks Ltd

Evidence Talks Ltd

A leading forensic computing authority developing unique digital forensic technologies. Tools that detect potential terrorists & criminals & used by the military, enforcement & intelligence commmunity

Netacea

Netacea

Netacea provides a revolutionary bot management solution that protects websites, mobile apps and APIs from malicious attacks such as scraping, credential stuffing and account takeover.

CyberNet Albania

CyberNet Albania

Cybernet Albania has been providing IT support and services to small businesses since 2016. We strive to eliminate your IT issues before they cause downtime and impact your operations.

ImpactQA

ImpactQA

ImpactQA is a global leading software testing & QA consulting company. Ten years of excellence. Delivering unmatched services & digital transformation to SMEs & Fortune 500 companies.

Cyber Command - Romania

Cyber Command - Romania

Cyber Command represents the military authority responsible for the development, protection and resilience of military IT networks and services that support the Romanian Force Structure.

Safe Systems

Safe Systems

Safe Systems provide compliance centric IT services for community banks and credit unions, ensuring that they are kept up to date on current technologies, security risks, and regulatory changes.

Nitrokey

Nitrokey

Nitrokey is the world-leading company in open source security hardware. Nitrokey develops IT security hardware for data encryption, key management and user authentication.

RealTyme

RealTyme

RealTyme is a secure communication and collaboration platform with privacy and human experience at its core.

Intelligent Technical Solutions (ITS)

Intelligent Technical Solutions (ITS)

We help businesses manage their technology. Intelligent Technical Solutions provide you with the right technical solution, so you can get back to running your business.

Ceeyu

Ceeyu

Ceeyu is an all-in-one cybersecurity ratings and third party risk management platform.

BTQ Technologies

BTQ Technologies

BTQ is a global quantum technology company focused on securing mission critical networks.