Today, the United States and the United Kingdom have taken action against seven Russian individuals for their involvement in the TrickBot cybercrime group. This group is responsible for developing malware such as TrickBot, BazarBackdoor, Anchor, and BumbleBee, which was used to support attacks by the Conti and Ryuk ransomware operations. The malware was initially used to steal online bank accounts, but later evolved to provide initial access to corporate networks. The TrickBot group was taken over by the Conti ransomware gang, who used the malware to facilitate or conduct numerous high-profile ransomware attacks. The ransomware strains known as Conti and Ryuk affected 149 UK individuals and businesses, extorting at least £27 million. In response, the US and UK have sanctioned seven individuals for their involvement in the TrickBot malware operation. This is the first time the UK has taken such action, and it is a result of a collaborative effort between the US Department of the Treasury and the UK's Foreign, Commonwealth, and Development Office; National Crime Agency; and His Majestys Treasury. The sanctions come after the ContiLeaks and TrickLeaks, which exposed internal conversations and personal information of the TrickBot members. As a result, the Conti gang shut down their operation and their members moved on to other ransomware operations. The individuals sanctioned today have had all their property and funds in the US and UK blocked, and any foreign financial institution that knowingly facilitates a transaction with them could be subject to US sanctions.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 09 Feb 2023 15:22:02 +0000