NIBS (credit image/Pixabay/ Ryan McGuire)A busy week for law enforcement as more malware infrastructure was dismantled and servers captured (see below). This ongoing string of takedowns comes from intelligence gleaned from servers captured in previous operations.

It shows how law enforcement worldwide shares the intelligence they gain from all takedowns. And how effectively that is being used to launch new attacks against cybercriminals and their organisations.

In other news, the Ministry of Justice admitted that the Legal Aid Agency has suffered a major cyber attack. Over 15 years of data was stolen, including a considerable amount of PII, including criminal records and payment data.

Dashlane announced the appointment of Christophe Frenet as its new Chief Product Officer. Frenet will lead Dashlane’s product vision, strategy, and innovation. He will be responsible for steering the direction of the firm’s Omnix platform. An AI-accelerated credential security solution unifying proactive intelligence, response, and access protection for enterprises.

BlueVoyant

BlueVoyant has been recognised in the latest Forrester report, The Managed Detection And Response Services In Europe Landscape, Q2 2025. The report provides information on MDR providers in Europe. It also shows how they differ and investigates options based on their size and market focus.

Milan Patel, Global Head of MDR at BlueVoyant, said, “Being proactive requires hands-on expertise in the security tools. Which includes implementation and onboarding optimization, to ensure the highest quality detections are available for monitoring and investigations.

“In addition, we go beyond traditional MDR to offer a full suite of proactive services to enterprises across Europe and around the globe through the BlueVoyant Cyber Defence Platform.”

Europol

Operation Endgame, Operation RapTor and working with Microsoft to take down Lumma are the highlights from Europol this week.

Operation Endgame

The latest action under Operation Endgame saw law enforcement capture 300 servers worldwide, neutralise 650 domains, and issue international arrest warrants against 20 targets. €3.5 million in cryptocurrency was also seized, bringing the total crypto seizures to €21.2 million, with the potential for more to come.

Previous operations undertaken by Operation Endgame have targeted botnets, with the largest coordinated attack on them in May 2024. This attack targeted organisations and malware that have emerged since then. It claims to have neutralised seven strains of malware, Bumblebee, Lactodectus, Qakbot, Hijackloader, DanaBot, Trickbot and Warmcookie.

Operation RapTor

Operation RapTor targeted networks that enabled the trafficking of drugs, weapons and counterfeit goods across Europe, the USA, Brazil and South Korea. 270 arrests took place in 10 countries, with 120 taking place in the USA. It saw multiple seizures of goods, including:

    • Over EUR 184 million in cash and cryptocurrencies
    • Over 2 tonnes of drugs, including amphetamines, cocaine, ketamine, opioids and cannabis
    • Over 180 firearms, along with imitation weapons, tasers and knives
    • 12,500 counterfeit products
    • More than 4 tonnes of illegal tobacco

Intelligence gathered from Operation SpecTor in 2023 led this operation. Authorities will be focused on analysing all servers, phones and records seized as part of this operation to lead future operations.

Lumma disrupted

Europol’s European Cybercrime Centre (EC3) and Microsoft’s Digital Crime Unit (DCU) have disrupted the infostealer, Lumma. It comes after Microsoft detected over 394,000 Windows computers infected with the malware. The action cut off communication between the tool and its victims.

The action saw over 1,300 domains seized by or transferred to Microsoft. That includes 300 domains actioned by law enforcement agencies. All the domains will now be directed to Microsoft sinkholes.

FBI

Matthew D. Lane, a student at Assumption University in Worcester, Mass., has been charged and pleaded guilty to hacking into the computer networks of two US-based companies and extorting the companies for ransoms.

The charges that Lane has pleaded guilty to include cyber extortion conspiracy, cyber extortion, unauthorised access to protected computers, and aggravated identity theft. He will be sentenced at a later date.

Kimberly Milka, Acting Special Agent in Charge of the Federal Bureau of Investigation, Boston Division, said, “Matthew Lane apparently thought he found a way to get rich quick, but this 19-year-old now stands accused of hiding behind his keyboard to gain unauthorized access to an education software provider to obtain sensitive data which was used in an attempt to extort millions of dollars.

“He also allegedly conspired to extort more money from a telecommunications provider over its confidential data. This alleged scheme has resulted in serious consequences and highlights the FBI’s ongoing commitment to bringing cyber criminals to justice, no matter what their motivation is for willfully breaking the law.”

ManageEngine

ManageEngine and Zensar Technologies have announced a strategic partnership to transform enterprise IT management. It will address critical industry challenges such as fragmented IT ecosystems. It will also cater to the growing need for real-time observability and unified operations for today’s enterprises.

Promoth Kumar, Chief Revenue Officer at ManageEngine, said, “Enterprises today face increasing complexity in managing their IT infrastructure, affecting productivity and overall success.

“This partnership with Zensar will provide businesses with a unified solution to streamline IT operations and enhance service delivery. By combining Zensar’s expertise with our advanced IT solutions, we aim to deliver real-time visibility and proactive incident management, ensuring seamless operations.”

National Cyber Security Centre

The National Cyber Security Centre has released a new advisory on a Russian cyber campaign. Released in conjunction with partners from ten countries, it shows how military unit 26165 of Russia’s GRU has been targeting the transport and delivery of support to Ukraine, along with multiple systems in NATO countries.

Unit 26165 – also known as APT 28 – was able to gain initial access to victim networks using a mix of previously disclosed techniques, including credential guessing, spear-phishing and exploitation of Microsoft Exchange mailbox permissions. It also targeted internet-connected cameras at Ukrainian border crossings and near military installations to monitor and track aid shipments to Ukraine.

noyb

noyb is considering bringing action against the latest proposal to harmonise and accelerate the GDPR. That is because the regulation appears to favour big tech over users. It claims that the new GDPR procedural regulation is overcomplicated and will lead to longer procedures. The result could be that deadlines that are already four times their projected timescale will balloon to as much as two years.

According to Max Schrems, “As far as we have heard, there is no final agreement on deadlines. However, the deadlines that are already agreed amount to 7 months just to plan a GDPR procedure and 4 months to issue a decision.

“Considering that there also needs to be an investigation, we likely talk about 2-3 years for a decision. The European Parliament originally asked for deadlines as short as 3 months. Many Member States have deadlines of 3 to 6 months.”

A German Regional Court in Cologne declined to issue an interim injunction stopping Meta from using user data to train its AI. The case was brought by the VZ NRW to prevent Meta from starting training, which cannot be reversed, until a full hearing could take place.

While other organisations plan action at the national level, noyb plans action at an EU level. That could lead to damages for 400 million European users. Such action is being taken as the Irish DPC again fails to regulate Meta.

US Department of Justice

The US Justice Department unsealed an indictment against a Russian citizen, Rustam Rafailevich Gallyamov, for leading the cyber gang that developed and deployed the Qakbot malware. It is also seeking the $24 million in cryptocurrency seized from Gallyamov during the course of the investigation.

Matthew R. Galeotti, Head of the Justice Department’s Criminal Division, said, “Today’s announcement of the Justice Department’s latest actions to counter the Qakbot malware scheme sends a clear message to the cybercrime community.

“We are determined to hold cybercriminals accountable and will use every legal tool at our disposal to identify you, charge you, forfeit your ill-gotten gains, and disrupt your criminal activity.”

Security news from the week beginning 12th May 2025

LEAVE A REPLY

Please enter your comment!
Please enter your name here