European and international law enforcement agencies have disrupted the KillSec ransomware group, seizing its infrastructure and data and making arrests, Europol said. The operation, called Operation KillSwitch, began on September 30 and was led by German authorities, with support from Europol, Eurojust, agencies in several countries, and cybersecurity company Group-IB.
Europol said KillSec emerged as a serious threat in 2024. Over the following two years, the group carried out roughly 1,000 attacks worldwide, at least half of which were likely successful. It targeted organizations in sectors including professional services, technology, healthcare and financial services.
Investigators found that the group had at least four members: a ringleader, developer, negotiator and affiliate. Europol has not publicly identified the alleged ringleader because the person is 16. The main developer recently turned 18, and many of the crimes attributed to him were committed while he was a minor. The investigation is ongoing, and the group may have had more members.
Group-IB analysts identified at least 274 victim organizations. The company said 35% were in the United States and 17% in India; Brazil, the UK, Australia and Colombia each accounted for 3%. Authorities confiscated 110 terabytes of data, five central servers, multiple domains and criminal proceeds. Europol’s wording suggests three people were arrested, but does not clearly establish whether the alleged ringleader was among them.
KillSec initially targeted Windows systems. In late 2024, it launched its KillSec 2.0 affiliate platform, which expanded to VMware ESXi hosts. By January 2025, it was recruiting affiliates and demanding 20% of each ransom.
Comments
0No comments yet. Be the first to comment.