Arrested: ransomware group DoppelPaymer

Arrested: ransomware group DoppelPaymer

Share post

Again the core members of a ransomware group were caught: the heads of the APT group DoppelPaymer were caught in Ukraine and Germany through a cooperation of the police, Europol, FBI and many other authorities. The group became known through the attack on the University Hospital Düsseldorf.

Already on February 28, 2023, the German State Criminal Police Office of North Rhine-Westphalia and the Ukrainian National Police, with the support of Europol, the Dutch police (Politie) and the United States Federal Bureau of Investigation, targeted suspected core members of the criminal group responsible for large-scale cyber attacks responsible for the DoppelPaymer ransomware.

🔎 The Ukrainian National Police assisted Europol in the raid (Image: Europol).

Doppel Palmer also attacked hospitals

The ransomware emerged in 2019 when cybercriminals started launching attacks on organizations and critical infrastructure and industries. Based on BitPaymer ransomware and part of the Dridex malware family, DoppelPaymer utilized a unique tool capable of compromising defense mechanisms by terminating the security-related process of the attacked systems. The DoppelPaymer attacks were also made possible by Emotet.

The ransomware was distributed through various channels, including phishing and spam emails with attached documents containing malicious code - either JavaScript or VBScript. The criminal group behind this ransomware relied on a double ransomware scheme and used a leak website launched by the criminal actors in early 2020. The German authorities are aware of 37 victims of this ransomware group, all of them companies. One of the most serious attacks was perpetrated against the University Hospital in Düsseldorf. In the US, victims paid at least 2019 million euros between May 2021 and March 40.

Tens of millions in loot

During the simultaneous actions, German officers searched the home of a German national believed to have played an important role in the DoppelPaymer ransomware group. Investigators are currently analyzing the confiscated devices to determine the exact role of the suspect in the structure of the ransomware group. At the same time, and despite the extremely difficult security situation that Ukraine is currently in due to the Russian invasion, Ukrainian police officers interrogated a Ukrainian national who is also suspected to be a member of the DoppelPaymer core group. Ukrainian officials searched two locations, one in Kiev and one in Kharkiv. During the searches, they confiscated electronic devices that are currently being forensically examined.

From the beginning of the investigation, Europol facilitated the exchange of information, coordinated international law enforcement cooperation and supported operational activities. Europol also provided analytical support by linking available data to various criminal cases inside and outside the EU, and assisted the investigations with cryptocurrency, malware, decryption and forensic analysis.

Editor/sel

More at Europol.com

 

Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more