-
Dream job: US soccer fans paid to watch every World Cup game
-
England left frustrated by Ghana in World Cup draw
-
Europe wilts under record heat as AC sales soar
-
Grieving Deschamps to miss France's final World Cup group game
-
Rubio rejects Iran tolls on Hormuz as deal strains multiply
-
Two-goal Ronaldo delights in silencing critics after 'attacks'
-
Cubans bid farewell to revolution hero Valdes
-
Morocco squad 'supporting' Hakimi despite impending rape trial
-
Ronaldo delights in silencing 'attacks' after making World Cup history
-
Airbus to inspect 16 A380s after cracks found on plane wings
-
'Paris in this heat is awful': Tourists change plans as sites close early
-
Bolivian government says cleared all protest roadblocks
-
'I'm back': Ronaldo scores at sixth World Cup as Portugal run riot
-
France has hottest-ever day as 'unbearable' heatwave keeps scorching Europe
-
US TV news host begs for info after kidnap note says mother is dead
-
Ronaldo double fires Portugal, England eye last 32
-
Ronaldo scores at sixth World Cup as Portugal run riot
-
Hollywood powerhouses bring AI fight to Europe
-
Portugal's Ronaldo first man to score at six World Cups
-
What is driving Europe's heatwave?
-
Rubio says US will not accept Iranian tolls on Hormuz
-
Spain's Oyarzabal happy to play through pain at World Cup
-
Marco Rubio in Gulf to reassure allies hit hard by Mideast war
-
US Supreme Court rules against man whose dreadlocks were cut off in prison
-
American Michele Kang agrees deal to buy French club Lyon
-
UN to begin evacuating stranded Mideast sailors after US-Iran talks
-
French farmers suffer arid crops, heat-stricken animals
-
Tech drags down world stocks, oil dips on supply hopes
-
Scorching heat shuts Paris landmarks early as France swelters
-
Shootout traps tourists at Rio sunrise lookout
-
Ipswich hire Gary O'Neil as manager
-
Heatwave sparks health warnings across Europe
-
Lake wins Wales captaincy race ahead of Morgan
-
Hundreds of schools close as UK braces for record-breaking heatwave
-
Tech names drag down world stocks, oil dips on supply hopes
-
Starmer vows 'orderly' transition as Labour MPs mull bid to be PM
-
Reports of Dupont inclusion in France squad 'bordering on annoying' says Galthie
-
ACTIVIST SHAREHOLDER FILES SCHEDULE 13D IN EQUUS TOTAL RETURN, INC.
-
England coach McCullum denies rift with 'good friend' Stokes
-
Europe: the world's fastest-warming continent
-
Taliban officials hold EU migration talks in Brussels
-
Gennaro Gattuso returns to coaching with Lazio after Italy debacle
-
Kenya halts US Ebola facility: health minister tells court
-
Why the heat is wreaking havoc on Europe's trains
-
Zelensky to skip key Ukraine conference in Poland over WWII row
-
Seoul leads rout for tech shares as oil prices dip
-
Europe heatwave closes schools, threatens health
-
India monsoon sweeps north but brings less rain than usual
-
Germany eyes longer working lives in pension reform plan
-
UK and markets await Burnham's economic plans
Four arrested in international anti-malware sweep
Authorities arrested four people and took down or disrupted more than 100 servers in the "largest ever" operation against botnets that deploy ransomware, Europol said Thursday.
Dubbed Operation Endgame, the sweep was initiated and led by France, Germany and the Netherlands, with a French official saying they wanted to act before this summer's Paris Olympics.
The attacks cost the victims, which were mainly companies and national institutions, hundreds of millions of euros, according to Dutch police, adding that the systems of millions of individuals were infected.
The May 27-29 operation led to one arrest in Armenia and three in Ukraine, with searches in both countries as well as in the Netherlands and Portugal, Europol said.
The servers were located in Bulgaria, Canada, Germany, Lithuania, the Netherlands, Romania, Switzerland, Britain, the United States and Ukraine.
In addition to the four arrests, eight fugitive suspects linked to the case will be added to Europe's Most Wanted list.
One of the suspects earned at least 69 million euros ($75 million) in cryptocurrency by renting out criminal infrastructure sites to disseminate ransomware, Europol said.
"This is the largest ever operation against botnets, which play a major role in the deployment of ransomware," the agency based in The Hague said.
A botnet is a network of computers infected by malware and controlled by hackers.
Authorities targeted malware "droppers" -- a type of software used to insert malicious software into a system -- named IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot.
Trickbot was used to launch ransomware attacks on US hospitals during the Covid pandemic.
- Pre-Olympics sting -
The operation had "a global impact on the dropper ecosystem", Europol said.
Droppers allow criminals to bypass security measures and deploy viruses, ransomware or spyware, the agency said.
The malicious software is generally installed via emails with infected links or Word and PDF attachments, according to Eurojust, the European Union Agency for Criminal Justice Cooperation.
The agency said the operation was ongoing, with more arrests expected.
"We wanted to do this operation before the Olympic Games," Nicolas Guidoux, head of the French police's cybercrime unit, told AFP.
He said it was "important to weaken the attacking infrastructure" and "limit their resources" before the global event, as authorities fear that it could be targeted by numerous cyberattacks.
Endgame also involved authorities from Denmark, Britain and the United States, with additional support from Armenia, Bulgaria, Lithuania, Portugal, Romania, Switzerland and Ukraine.
- SystemBC and Pikabot -
The investigation was launched in 2022.
German cybercrime prosecutor Benjamin Krause said health, education and public administration institutions were targeted.
Hackers would encrypt files or whole systems to block access to them and then demand money to unlock them, Krause said at a news conference, adding that such attacks threatened "the existence of companies".
French investigators identified the administrator of the SystemBC dropper, which Europol said "facilitated anonymous communication between an infected system" and "command-and-control servers".
The administrator of Pikabot -- a Trojan horse allowing the deployment of ransomware, the remote takeover of computers and data theft -- was also identified by French authorities.
French police participated in the suspect's arrest and house search in Ukraine, with authorisation from local authorities, said Paris prosecutor Laure Beccuau.
Guidoux said the number of victims will be known only after the dismantled servers are analysed.
Cybersecurity experts said Operation Endgame helped to destabilise a criminal ecosystem that is difficult to crack.
"The dropper network is a piece of infrastructure that makes life easier for many cybercriminal groups," said Jerome Saiz, founder of cybersecurity firm OPFOR Intelligence.
F.Müller--BTB