Spanish cops cuff 11 for €1m-a-year ransomware scam

Interpol says Reveton malware ring has been smashed


Spanish police have arrested 11 individuals suspected of running a €1m a year ransomware scam using malware that posed as a message from law enforcement.

Law enforcement agencies in Spain first became interested in the Reveton malware after hundreds of complaints from victims of the scam starting flooding in at the beginning of 2011. Trend Micro and the Spanish agencies worked with the European Cybercrime Centre (EC3) at Europol in an operation coordinated by Interpol over the months that followed - sharing intelligence, samples and related technical detail. Police said the research allowed them to map of the criminal network infrastructure including traffic redirection and command-and-control servers. They then conducted raids on premises, seizing IT equipment and credit cards used to cash out the money that victims had paid.

In a statement (Spanish), cops said that since it was detected in May 2011, there had been more than 1,200 complaints about the so-called "POLICE VIRUS" (Reveton drive-by malware).

Police said this intelligence led to the arrest of 11 individuals. One of the suspects, an unnamed 27-year-old, is suspected to be the boss of the gang that produces the Reveton ransomware.

This Russian national was arrested in Dubai, United Arab Emirates. Spanish authorities have filed an extradition warrant. Along with this key arrest, police said they had run a takedown operation focusing on the lower-ranked members of gang, in connection with which they made several additional arrests.

Police said lower-ranked members in the gang were involved in monetisation of the PaySafeCard/Ukash vouchers received as payment in the scam. The gang had a branch in Spain's Costa Del Sol that exchanged these vouchers and converted them into real money, which would then be sent to the main group in Russia. Europol said in a separate statement:

The financial cell of the network specialised in laundering the proceeds of their crimes, obtained in the form of electronic money. For this, the gang employed both virtual systems for money laundering and other traditional systems using various online gaming portals, electronic payment gateways or virtual coins.

Spanish cops said 10 of the suspects had been arrested in connection with allegations of money-laundering activity. Six of the cuffed suspects are Russian, two Ukrainian and two Georgian, but all of them were based in Spain, police said.

Spanish cops reckon the fraudsters behind the scam were pulling in €1m a year.

"This coordinated activity (in much the same way as the Trend Micro/FBI action against the DNS Changer gang last year), leading directly to the arrest of individuals believed to be actively engaged in cybercrime, rather than simply taking down associated infrastructure, should serve as a model for how the security industry and law enforcement can effectively cooperate int he fight against online crime," said Rik Ferguson, director of security research and communications at Trend Micro.

Trend Micro has blogged about the arrests here.

Police ransomware locks up systems and accuses the user of using illegal filesharing networks or of child abuse image distribution. The ransomware uses police logos to make it look like it came from a law enforcement agency to convince victims to cough a "fine" of around €100 using cash vouchers in order to unlock their computers. More details of the Reveton ransomware at the centre of the scam can be found here (PDF). ®

Broader topics


Other stories you might like

  • DigitalOcean tries to take sting out of price hike with $4 VM
    Cloud biz says it is reacting to customer mix largely shifting from lone devs to SMEs

    DigitalOcean attempted to lessen the sting of higher prices this week by announcing a cut-rate instance aimed at developers and hobbyists.

    The $4-a-month droplet — what the infrastructure-as-a-service outfit calls its virtual machines — pairs a single virtual CPU with 512 MB of memory, 10 GB of SSD storage, and 500 GB a month in network bandwidth.

    The launch comes as DigitalOcean plans a sweeping price hike across much of its product portfolio, effective July 1. On the low-end, most instances will see pricing increase between $1 and $16 a month, but on the high-end, some products will see increases of as much as $120 in the case of DigitalOceans’ top-tier storage-optimized virtual machines.

    Continue reading
  • GPL legal battle: Vizio told by judge it will have to answer breach-of-contract claims
    Fine-print crucially deemed contractual agreement as well as copyright license in smartTV source-code case

    The Software Freedom Conservancy (SFC) has won a significant legal victory in its ongoing effort to force Vizio to publish the source code of its SmartCast TV software, which is said to contain GPLv2 and LGPLv2.1 copyleft-licensed components.

    SFC sued Vizio, claiming it was in breach of contract by failing to obey the terms of the GPLv2 and LGPLv2.1 licenses that require source code to be made public when certain conditions are met, and sought declaratory relief on behalf of Vizio TV owners. SFC wanted its breach-of-contract arguments to be heard by the Orange County Superior Court in California, though Vizio kicked the matter up to the district court level in central California where it hoped to avoid the contract issue and defend its corner using just federal copyright law.

    On Friday, Federal District Judge Josephine Staton sided with SFC and granted its motion to send its lawsuit back to superior court. To do so, Judge Staton had to decide whether or not the federal Copyright Act preempted the SFC's breach-of-contract allegations; in the end, she decided it didn't.

    Continue reading
  • US brings first-of-its-kind criminal charges of Bitcoin-based sanctions-busting
    Citizen allegedly moved $10m-plus in BTC into banned nation

    US prosecutors have accused an American citizen of illegally funneling more than $10 million in Bitcoin into an economically sanctioned country.

    It's said the resulting criminal charges of sanctions busting through the use of cryptocurrency are the first of their kind to be brought in the US.

    Under the United States' International Emergency Economic Powers Act (IEEA), it is illegal for a citizen or institution within the US to transfer funds, directly or indirectly, to a sanctioned country, such as Iran, Cuba, North Korea, or Russia. If there is evidence the IEEA was willfully violated, a criminal case should follow. If an individual or financial exchange was unwittingly involved in evading sanctions, they may be subject to civil action. 

    Continue reading

Biting the hand that feeds IT © 1998–2022