GBHackers

16-Year-Old Suspected KillSec Ransomware Leader Arrested in International Operation


International law enforcement authorities have arrested three suspects linked to the KillSec ransomware group, including a 16-year-old who is alleged to be the operation’s administrator and primary operator.

This coordinated action, announced on October 1, involved agencies from nine countries and was supported by Eurojust and Europol.

KillSec Ransomware Leader Arrested

KillSec, which has been active since 2024, is suspected of carrying out nearly 1,000 attacks against organizations worldwide. Investigators believe the group primarily targeted poorly secured entry points, particularly those related to cloud storage, to infiltrate victim environments.

Once they gained access, the attackers allegedly exfiltrated sensitive data to infrastructure they controlled. They used the threat of public exposure to extort victims.

Rather than relying solely on encryption-based disruption, KillSec reportedly utilized a data theft and extortion model. Victims were sent samples of their stolen files as proof of compromise and were warned that the data would be published if ransom demands were not met.

In cases where organizations declined to pay, the group allegedly made the stolen material available for free download, thereby increasing the potential impact on affected businesses, customers, and partners.

Authorities identified several individuals believed to have performed distinct operational functions within the group, including administrator, developer, negotiator, and affiliate.

The 16-year-old suspect is accused of serving as KillSec’s main administrator and operator, while a second suspect, described as a developer who recently turned 18, was allegedly a minor during part of the criminal activity being investigated.

The group reportedly used online aliases to conceal its members’ identities and relied on encrypted messaging platforms for communication. Investigators traced infrastructure, examined cryptocurrency transactions, and pursued digital evidence to map the group’s alleged operations and financial flows.

The action day resulted in eight house searches across Spain, Greece, the United Kingdom, and Romania. Authorities seized evidence, assets, and five servers allegedly used to store victim data, as well as domains operated by KillSec.

Investigators also secured at least 110 TB of stolen data, a significant collection that may help law enforcement identify previously unknown victims, additional intrusions, and other alleged participants.

Eurojust coordinated judicial authorities from Belgium, Finland, Germany, Greece, Romania, Spain, Switzerland, the United Kingdom, and the United States.

A joint investigation team involving Belgium, Germany, Greece, and Romania supported the case. At the same time, a Eurojust coordination center helped plan and manage the international operation.

Europol contributed intelligence reports on KillSec’s activity, connected investigators with private-sector partners, and provided specialized assistance for cryptocurrency tracing and digital forensics.

The operation involved various organizations, including the FBI’s San Juan Field Office, the U.S. Attorney’s Office for the District of Puerto Rico, the UK’s Eastern Region Special Operations Unit, Spanish law enforcement bodies, Romanian anti-organized crime authorities, German federal and state police, and national agencies in the other participating countries.

Investigators will now analyze the seized devices, servers, and datasets, while continuing efforts to trace ransom proceeds. This case underscores how ransomware crews increasingly rely on data extortion, cloud access vulnerabilities, cryptocurrency payments, and cross-border infrastructure, requiring equally coordinated international responses.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link