-
S. Africa deploys police as anti-migrant protests loom
-
Thousands from Philippine sect protest pro-Duterte senator's graft case
-
Monaco parcel bomb blast wounds Ukrainian oligarch
-
South Africa repatriations top 25,000 ahead of anti-immigrant ultimatum
-
Sweden face France's attacking firepower at the World Cup
-
Taiwan raids tech firms in China AI chip smuggling probe
-
Online same-sex romance series embrace AI 'freedom'
-
Morocco 'unstoppable' says coach after Netherlands thriller
-
New Oxford academic centre symbolises UK's big-donor era
-
Russia's small businesses pay the price of spiralling Ukraine war
-
Trump says Iran meeting set in Qatar, despite uncertainty
-
Paraguay shock Germany as Brazil, Morocco advance at World Cup
-
Morocco down Netherlands to reach World Cup last 16
-
NASA robot mission aiming to rescue space telescope
-
Asian stocks unable to track Wall St higher, yen holds at 40-year low
-
Mouse-that-roared Paraguay savors World Cup win over Germany
-
'We came from nothing': DR Congo dreams of England World Cup upset
-
Taiwan's ageing seaweed harvesters hope younger women wade in
-
Peruvian political heir Fujimori wins presidency
-
Key Venezuela port opens with US aid, as burials begin
-
What to expect as EU small parcel levy kicks in
-
Ambitious Japan search for answers after World Cup exit
-
Nagelsmann says won't 'run away' after Germany World Cup exit
-
How NATO will try to keep Trump happy at Ankara summit
-
Paraguay coach salutes 'extraordinary' World Cup win over Germany
-
Ultra-wealthy Chinese exile in New York sentenced to 30 years for fraud
-
Japan fans stunned as Brazil end their World Cup dream
-
Years on, families bury 68 Indigenous victims of Guatemala civil war
-
'Powerhouse' Haaland leads by example at World Cup: Norway coach Solbakken
-
'Deliberate' Monaco explosion wounds Ukrainian oligarch
-
Sadness and joy as breakaway Catholic group nears schism
-
Paraguay shock Germany, Brazil advance at World Cup
-
HUNTING/HER Headhunter Talk with EnBW Board Member & CHRO Colette Rückert-Hennen
-
Germany dumped out by Paraguay in seismic World Cup shock
-
'I recognized her ring': identifying Venezuela's dead in a makeshift morgue
-
More than 1,000 drones detected since start of World Cup: FBI
-
Tuchel defensive headache as England ready for DR Congo clash
-
Extreme heat warning issued for World Cup host Kansas City
-
US reopens Venezuela port as quake deaths top 1,700
-
Bloodied but unbowed: Sinner, Djokovic survive Wimbledon scares
-
Coach says Japan getting closer to World Cup glory despite defeat
-
Djokovic battles past Wu in 'challenging' Wimbledon first round
-
NBA Grizzlies deal Morant to Portland: report
-
World Bank drops climate finance targets in renewed action plan
-
Sweden ready for 'game of our lives' in France World Cup clash
-
Ancelotti says never doubted 'suffering' Brazil would score
-
MLS Chicago Fire announce signing of Poland's Lewandowski
-
Venezuela's quake-hit La Guaira port 'operational': US military
-
Tech rebound lifts Dow to record, yen hits 40-year low against dollar
-
Martinelli late show as Brazil down Japan to reach World Cup last 16
Four arrested in major international anti-malware sweep
Authorities arrested four people and took down or disrupted more than 100 servers in the "largest ever" operation against botnets that deploy ransomware, Europol said Thursday.
Dubbed Operation Endgame, the sweep was initiated and led by France, Germany and the Netherlands, with a French official saying they wanted to act before this summer's Paris Olympics.
The attacks cost the victims, which were mainly companies and national institutions, hundreds of millions of euros, according to Dutch police, adding that the systems of millions of individuals were infected.
The May 27-29 operation led to one arrest in Armenia and three in Ukraine, with searches in both countries as well as in the Netherlands and Portugal, Europol said.
The servers were located in Bulgaria, Canada, Germany, Lithuania, the Netherlands, Romania, Switzerland, Britain, the United States and Ukraine.
In addition to the four arrests, eight fugitive suspects linked to the case will be added to Europe's Most Wanted list.
One of the suspects earned at least 69 million euros ($75 million) in cryptocurrency by renting out criminal infrastructure sites to disseminate ransomware, Europol said.
"This is the largest ever operation against botnets, which play a major role in the deployment of ransomware," the agency based in The Hague said.
A botnet is a network of computers infected by malware and controlled by hackers.
Authorities targeted malware "droppers" -- a type of software used to insert malicious software into a system -- named IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot.
Trickbot was used to launch ransomware attacks on US hospitals during the Covid pandemic.
- Pre-Olympics sting -
The operation had "a global impact on the dropper ecosystem", Europol said.
Droppers allow criminals to bypass security measures and deploy viruses, ransomware or spyware, the agency said.
The malicious software is generally installed via emails with infected links or Word and PDF attachments, according to Eurojust, the European Union Agency for Criminal Justice Cooperation.
The agency said the operation was ongoing, with more arrests expected.
"We wanted to do this operation before the Olympic Games," Nicolas Guidoux, head of the French police's cybercrime unit, told AFP.
He said it was "important to weaken the attacking infrastructure" and "limit their resources" before the global event, as authorities fear that it could be targeted by numerous cyberattacks.
Endgame also involved authorities from Denmark, Britain and the United States, with additional support from Armenia, Bulgaria, Lithuania, Portugal, Romania, Switzerland and Ukraine.
- SystemBC and Pikabot -
The investigation was launched in 2022.
German cybercrime prosecutor Benjamin Krause said health, education and public administration institutions were targeted.
Hackers would encrypt files or whole systems to block access to them and then demand money to unlock them, Krause said at a news conference, adding that such attacks threatened "the existence of companies".
French investigators identified the administrator of the SystemBC dropper, which Europol said "facilitated anonymous communication between an infected system" and "command-and-control servers".
The administrator of Pikabot -- a Trojan horse allowing the deployment of ransomware, the remote takeover of computers and data theft -- was also identified by French authorities.
French police participated in the suspect's arrest and house search in Ukraine, with authorisation from local authorities, said Paris prosecutor Laure Beccuau.
Guidoux said the number of victims will be known only after the dismantled servers are analysed.
G.Haefliger--VB