Police take down dangerous KillSec ransomware gang — and find out it's being run by a teenager
Some people have been arrested, with servers, domains, and proceeds, confiscated, too.
Operation KillSwitch successfully dismantled the dangerous KillSec ransomware gang, seizing their infrastructure, cryptocurrency, and massive amounts of data. This operation, led by German authorities with the help of Europol, Eurojust, and multiple national law enforcement agencies, as well as cybersecurity companies like Group-IB, marked the end of the notorious KillSec group.
KillSec, which emerged in 2024, made around 1,000 attacks worldwide, mostly on smaller to medium-sized organizations in sectors like healthcare, finance, and technology. The group's attacks primarily targeted organizations with sensitive data and potentially weak cybersecurity measures. While large enterprises and government organizations were targeted as well, size did not appear to be the main factor in selection.
Investigations revealed that KillSec was run by at least four individuals, including a 16-year-old ringleader whose identity remains undisclosed. The main developer recently turned 18, but many of the group's crimes were committed when he was a minor. It's possible the group was even larger, as the investigation is ongoing. Group-IB identified over 274 victim organizations, with most being from the United States (35%), followed by India, Brazil, the UK, Australia, and Colombia.
The group targeted various sectors, including financial services, healthcare, government organizations, and large enterprises. Notable victims included a major insurer, investment firms, and a popular consumer app with millions of users. During the operation, three individuals were arrested, though the ringleader was not among them.
Law enforcement seized 110 terabytes of data, the group's criminal proceeds in cryptocurrency, five central servers, and the infrastructure used to manage the group's activities and store stolen data. Multiple domains associated with KillSec were also seized and now display standard seizure notices. Police conducted eight house searches across Europe in Spain, Greece, Romania, and the United Kingdom.
Initially, KillSec focused on the Windows platform, but later released its KillSec 2.0 affiliate platform, expanding into VMware ESXi virtualization hosts capable of shutting down virtual machines, deleting snapshots, erasing logs, and more. By January 2025, the group openly recruited "skilled pentesters" requiring a forum reputation or a USD 1,000 deposit and demanded 20% of each ransom from affiliates.
Despite the group's significant impact, Operation KillSwitch's success demonstrates the importance of identifying and apprehending those behind cybercriminal activities, not just shutting down servers. The operation's contributors, including Europol, national law enforcement agencies, and cybersecurity firms like Group-IB, are proud of their contributions to bringing the KillSec gang to justice and committed to continuing the fight against cybercrime.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.