Global law enforcement action in Asia nets large infrastructure seizure, 32 arrests
Full article789 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Operation Secure targeted malicious IPs, domains and servers used for infostealer operations that claimed more than 216,000 victims.
Listen to this article
0:00
Learn more.
Authorities from 26 countries scored another win in the global crackdown on cybercrime earlier this year, chipping away at multiple operations in Asia by arresting dozens of alleged cybercriminals and seizing a vast array of infrastructure, Interpol announced Wednesday.
Operation Secure, which ran through the first four months of the year, targeted physical and virtual systems used for infostealer operations that claimed more than 216,000 victims, officials said.
Law enforcement agencies seized 41 physical servers, more than 100 GB of data and took down more than 20,500 malicious IPs and domains. Local police in Vietnam, Sri Lanka and Nauru arrested a combined 32 suspects as part of the operation, according to officials.
Global authorities said 69 infostealer variants were investigated as part of the operation, including prolific infostealer malware such as Lumma, Risepro and Meta Stealer, the cybercriminals command-and-control infrastructure and accounts used to advertise the malware and stolen data.
The takedowns and arrests come amid a recent burst of law enforcement action against cybercrime. During the past few weeks, authorities seized and took down infrastructure supporting the counter antivirus service AVCheck, the prolific Lumma Stealer infostealer operation, DanaBot’s malware-as-a-service operations, and hundreds of domains and servers used across several leading malware strains.
“Interpol continues to support practical, collaborative action against global cyber threats,” Neal Jetton, Interpol’s director of cybercrime, said in a prepared statement. “Operation Secure has once again shown the power of intelligence sharing in disrupting malicious infrastructure and preventing large-scale harm to both individuals and businesses.”
The Asia and South Pacific Joint Operations Against Cybercrime Project organized the regional Operation Secure initiative with threat intelligence assistance from Group-IB, Kaspersky and Trend Micro.
Authorities said they sent notices to more than 216,000 victims who had personally identifiable information stolen by the infostealers, including credentials, cookies, credit card details and cryptocurrency account data.
“The compromised credentials and sensitive data acquired by cybercriminals through infostealer malware often serve as initial vectors for financial fraud and ransomware attacks,” Group-IB CEO Dmitry Volkov said in a blog post. “By sharing actionable intelligence with INTERPOL and local law enforcement agencies, we are helping to dismantle the infrastructure behind these attacks, and protecting both organizations and individuals globally.”
Acting on information shared by Interpol, the Hong Kong Police Force identified 117 command-and-control servers hosted across 89 internet service providers, which the cybercriminals used to launch and manage their malicious campaigns.
The group of countries involved in Operation Secure include: Brunei, Cambodia, Fiji, Hong Kong, India, Indonesia, Japan, Kazakhstan, Kiribati, Korea, Laos, Macau, Malaysia, Maldives, Nauru, Nepal, Papua New Guinea, the Philippines, Samoa, Singapore, Solomon Islands, Sri Lanka, Thailand, Timor-Leste, Tonga, Vanuatu and Vietnam.
More Scoops
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims of various social-engineering scams.
Microsoft disrupts cybercrime service that abused software verification systems en masse
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/operation-secure-asia-takedown/