Alleged Ryuk ransomware gang member arrested in Ukraine and extradited to US
乌克兰将一名涉嫌参与Ryuk勒索软件团伙的男子引渡至美国,该男子被指控参与超1亿美元的网络攻击活动,并负责寻找企业网络漏洞以协助勒索软件攻击。警方查获了大量加密资产、豪车及土地。 2025-6-19 14:1:52 Author: therecord.media(查看原文) 阅读量:17 收藏

Ukrainian authorities said a suspected member of the Ryuk ransomware gang has been extradited to the U.S., where he faces charges over cyberattacks that extorted more than $100 million from victims worldwide.

The 33-year-old foreign national was arrested in Kyiv in April at the request of U.S. law enforcement and handed over to American authorities earlier this week, Ukraine’s Office of the Prosecutor General said on Wednesday. 

The office did not provide the suspect’s name. The U.S. Department of Justice has not issued a statement about the extradition. Thursday was a holiday for the U.S. government.

Ukrainian investigators said the man was “engaged in searching for vulnerabilities in the corporate networks of the victim companies” — or what cybersecurity experts call an “initial access broker.” Police said they seized more than $600,000 in crypto assets, nine luxury vehicles and 24 plots of land.

The group launched over 2,400 ransomware attacks in multiple countries, encrypting victims’ data and demanding cryptocurrency payments in exchange for access, authorities said. It is believed to have used the Ryuk ransomware strain in many of the attacks, which targeted corporations, critical infrastructure and industrial enterprises across the world, typically for financial gain.

Ryuk was first detected in August 2018, when it began attacking large organizations with demands for high ransom payments. The malware has previously been linked to Russian cybercriminals.

Ukrainian authorities said the suspect had previously been placed on an international wanted list by the FBI. The bureau’s public Cyber Most Wanted list contains more than 150 individuals, including alleged Russian cybercriminals.

The extradition comes after a broader international crackdown in late 2023 involving law enforcement agencies from seven countries, including the U.S., Germany, France and the Netherlands. The joint operation targeted ransomware actors linked to Ryuk, LockerGoga, MegaCortex, HIVE and Dharma.

The U.S. government has previously taken action against Ryuk’s money laundering operations.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/alleged-ryuk-member-arrest-ukraine-extradited-us
如有侵权请联系:admin#unsafe.sh