Interpol identifies 9,000 computers in Asia owned by hackers, used to launch ransomware
Full article651 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Nearly 9,000 computer servers based in southeast Asia are infected with or currently dispensing malware, according to a newly unveiled Interpol-led operation heavily supported by multiple private sector cybersecurity firms and domestic law enforcement agencies. Hundreds of compromised websites popularly used in Southeast Asia, including regional government portals, were also identified as under the control of hackers, Interpol announced Monday.
Nearly 9,000 computer servers based in southeast Asia are infected with or currently dispensing malware, according to a newly unveiled Interpol-led operation heavily supported by multiple private sector cybersecurity firms and domestic law enforcement agencies.
Hundreds of compromised websites popularly used in Southeast Asia — including regional government portals — also were identified as under the control of hackers, Interpol announced Monday.
The news underscores an increasingly international effort between national law enforcement agencies and the broader digital defense industry to collaborate on cybercrime fighting operations. An assistant attorney general for the Justice Department’s Criminal Division, Leslie Caldwell, said last year that the FBI would need to rely on foreign help to stop hackers in the future.
“Sharing intelligence was the basis of the success of this operation, and such cooperation is vital for long term effectiveness in managing cooperation networks for both future operations and day to day activity in combating cybercrime,” Noboru Nakatani, the executive director for Interpol Global Complex for Innovation, said in a statement.
Interpol compiled and provided individual “Cyber Activity Reports” to the governments of Indonesia, Malaysia, Myanmar, Philippines, Singapore, Thailand and Vietnam. The reports contain actionable recommendations to curb cybercrime, but there is no legal framework to compel countries to follow the guidance.
Interpol said several companies contributed to the investigation, including Trend Micro, Kaspersky Lab, Cyber Defense Institute, Booz Allen Hamilton, British Telecom, Fortinet and Palo Alto Networks.
Among the roughly 9,000 infected servers, Interpol found hoards of zombie computers preconfigured to launch phishing email scams, ransomware-style viruses, distributed denial of service-style attacks and targeted intrusions into financial institutions. The investigation into who originally hacked into these computers and what their motives are continues.
“For many of those involved, this operation helped participants identify and address various types of cybercrime which had not previously been tackled in their countries,” said Chairman of Interpol’s Eurasian cybercrime working group Superintendent Francis Chan in a statement. “It also enabled countries to coordinate and learn from each other by handling real and actionable cyber intelligence provided by private companies via INTERPOL, and is a blueprint for future operations.”
Interpol is calling the operation an example for how law enforcement can proactively investigate vulnerabilities before victims report damages.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/interpol-identifies-9000-computers-asia-owned-hackers-used-launch-ransomware/