logo
$24M in crypto, 30 Bitcoins, and $700K seized as FBI takes down Russian hacker behind 700,000 computer ransomware army in Operation Endgame

$24M in crypto, 30 Bitcoins, and $700K seized as FBI takes down Russian hacker behind 700,000 computer ransomware army in Operation Endgame

Economic Times24-05-2025
Reuters FBI and international allies seize $24M in crypto from Russian hacker Rustam Gallyamov, accused of turning 700,000 computers into a global ransomware army under Qakbot malware operation
For thousands of people around the world, the nightmare began the same way: a frozen screen, a blinking message, and a demand for money. Doctors, small business owners, factory workers, and even school staff found their computers suddenly hijacked.
The US Department of Justice has indicted Rustam Rafailevich Gallyamov, a 48-year-old Russian national from Moscow, for leading a global cybercriminal enterprise responsible for the notorious Qakbot malware. Alongside the charges, the Justice Department announced it had seized over $24 million in cryptocurrency linked to Gallyamov's cybercrime empire. These funds are now targeted to be returned to the victims who suffered from these attacks.
Victims ranged from small dental offices in Los Angeles to technology firms in Nebraska, manufacturing companies in Wisconsin, and even real estate businesses in Canada.
This indictment was unsealed on Thursday, May 22, 2025, and marks a crucial moment in America's ongoing battle against ransomware attacks that have plagued organizations worldwide. Matthew R. Galeotti, Head of the Justice Department's Criminal Division, emphasized the significance of this action: "Today's announcement of the Justice Department's latest actions to counter the Qakbot malware scheme sends a clear message to the cybercrime community. We are determined to hold cybercriminals accountable and will use every legal tool at our disposal to identify you, charge you, forfeit your ill-gotten gains, and disrupt your criminal activity."
Gallyamov is accused of developing and deploying Qakbot since 2008, a sophisticated malware that infected over 700,000 computers globally. The malware facilitated ransomware attacks by granting access to co-conspirators who deployed various ransomware strains, including Conti, REvil, Black Basta, and Dopplepaymer. Despite a multinational operation targeting him in August 2023 that disrupted the Qakbot botnet, Gallyamov allegedly continued his cybercriminal activities.'Mr. Gallyamov's bot network was crippled by the talented men and women of the FBI and our international partners in 2023, but he brazenly continued to deploy alternative methods to make his malware available to criminal cyber gangs conducting ransomware attacks against innocent victims globally,' said Assistant Director in Charge Akil Davis of the FBI's Los Angeles Field Office.He and his associates shifted tactics, employing "spam bomb" attacks to deceive employees into granting network access, leading to further ransomware deployments as recently as January 2025.As a result, the FBI under its 'Operation Endgame' seized more than 30 bitcoins and $700,000 in USDT tokens from Gallyamov under a seizure warrant executed on April 25, the Department of Justice confirmed in a statement.The Justice Department also filed a civil forfeiture complaint to seize over $24 million in cryptocurrency linked to Gallyamov's illicit activities. This was done not only to prosecute cybercriminals but also to recover assets to compensate victims.The indictment is part of Operation Endgame, a coordinated international effort involving law enforcement agencies from the United States, France, Germany, the Netherlands, Denmark, the United Kingdom, and Canada. This operation has dismantled key infrastructures of several malware strains, including Qakbot, DanaBot, Trickbot, and others, by taking down approximately 300 servers and neutralizing 650 domains worldwide.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Jeffrey Epstein files release: U.S. President Donald Trump named by accuser
Jeffrey Epstein files release: U.S. President Donald Trump named by accuser

Economic Times

time2 hours ago

  • Economic Times

Jeffrey Epstein files release: U.S. President Donald Trump named by accuser

Agencies In a lengthy post, Trump claimed "all these people want to talk about, with strong prodding by the Fake News and the success starved Dems, is the Jeffrey Epstein Hoax." It was the summer of 1996 when Maria Farmer went to law enforcement to complain about Jeffrey Epstein. At the time, she said, she had been sexually assaulted by Epstein and his longtime partner, Ghislaine Maxwell. Farmer, then in her mid-20s, had also learned about a troubling encounter that her younger sister -- then a teenager -- had endured at Epstein's ranch in New Mexico. And she described facing threats from Epstein. Farmer said that when she discussed her concerns with the New York Police Department, then with the FBI, she also urged them to take a broader look at the people in Epstein's orbit, including Donald Trump, then still two decades from being elected president. She repeated that message, she said, when the FBI interviewed her again about Epstein in 2006. Her account is among the clearest indications yet of how Trump might have come to be named in the unreleased investigative files in the Epstein case, a matter that has generated another political uproar in recent weeks. Donald Trump, Bill Clinton In interviews over the past week about what she told the authorities, she said she had no evidence of criminal wrongdoing by Epstein's associates. But she said she was alarmed by what she saw as Epstein's pattern of pursuing girls and young women while building friendships with prominent people, including Trump and President Bill like the ones that targeted Epstein often explore a wide range of tips, evidence, recollections and relationships, little of which ends up being used in court records or as the basis for criminal prosecution. Epstein's voluminous investigative file contains many records that have not been made public, but that became the focus of claims, long stoked by Trump's allies, that authorities might have covered up the involvement of other rich and powerful men. Now, after his attorney general and FBI director abruptly abandoned their earlier promises to reveal everything about the Epstein files and said, in effect, that there was nothing to see, Trump's ties to Epstein are under renewed scrutiny, leading to questions about what so-far-undisclosed appearances he might have in the investigative record. Farmer said she has long wondered how law enforcement agencies handled her complaints in 1996 and she said she has been wondering in particular whether federal authorities did anything with her concerns about Trump. She said that she raised his name both times, not only because he seemed so close to Epstein but because of an encounter, which she has previously described publicly, that she said she had with Trump in Epstein's New York Chit to Donald TrumpThe story of Farmer's efforts to call law enforcement attention to Epstein and his circle shows how the case files could contain material that is embarrassing or politically problematic to Trump, even if it is largely extraneous to Epstein's crimes and was never fully investigated or it underscores the complexities of opening up to scrutiny all the leads that investigators pursued, the evidence they gathered and the interviews they conducted, little of which ever went before a judge or enforcement agencies have not accused Trump of any wrongdoing related to Epstein, and he has never been identified as a target of any associated investigation. Trump last week called for relevant grand jury testimony in the prosecution of Epstein to be publicly released, and has repeatedly dismissed any notion that he has something to hide. Even if that testimony is released, it is unlikely to shed much light on the relationship between the two men, which did not figure prominently in Epstein's criminal cases. Q1. What are Epstein files?A1. Jeffrey Epstein's crimes are listed in Epstein files. Q2. Who is President of USA? A2. President of USA is Donald Trump.

DOJ Probing for Collusion in CLO Market During Libor Transition
DOJ Probing for Collusion in CLO Market During Libor Transition

Mint

time10 hours ago

  • Mint

DOJ Probing for Collusion in CLO Market During Libor Transition

The US Justice Department is conducting a criminal antitrust investigation into whether some investors in collateralized loan obligations colluded to bolster their positions as markets transitioned away from the scandal-plagued London interbank offer rate in early 2023, according to people familiar with the matter. Antitrust prosecutors in New York have sent subpoenas to financial firms as they seek to determine whether investors with an equity stake in the $1.3 trillion CLO market illegally coordinated as the underlying buyout debt was repriced, said the people, who asked not to be identified discussing the confidential probe. The investigation was opened about a year-and-a-half ago, the people said. A spokesperson for the Justice Department declined to comment. In the last few months of 2022 and early 2023 — shortly before the final phaseout of Libor — a flurry of companies in the leveraged loan market rushed to switch the benchmarks on their debt. Often, they tried to exclude an adjustment that was meant to compensate investors for the fact that the Secured Overnight Financing Rate — the debt's new benchmark — consistently printed below Libor. CLO managers, who repackage leveraged loans into bonds of varying risk and size, saw how some companies were about to reap benefits during that transition if that additional spread wasn't added, as it lowered the interest the companies paid. The most junior holders of the bonds they issued, also known as equity, stood to lose millions as they get paid last after every other investor in the bond has received their payments. Communications between CLO equity holders near the transition deadline is part of what is being investigated by prosecutors, said the people familiar with the matter. CLO equity investors were particularly exposed during the transition because their returns depend on the excess cash flows from underlying loans after higher-ranking CLO debt holders have been paid, and because of the significant leverage built into the structures. Smaller interest payments mean there's less left over for them to pocket. Antitrust law bars competitors from colluding for economic gain. Because each CLO investor is a separate entity, it could potentially be illegal for them to agree with each other on the financial terms for an investment. In criminal collusion or price-fixing cases, prosecutors must show evidence of an agreement, but don't need to provide proof of economic harm, potentially giving them an advantage if a case goes to trial. Still, if the government ultimately brings charges, it would need to convince a jury the actions came from collusion instead of firms reaching the same decision independently. This article was generated from an automated news agency feed without modifications to text.

Russia's FIERY Military Action After Putin City Bombed; Moscow SMASHES Zelensky's 'POWERFUL WEAPONS'
Russia's FIERY Military Action After Putin City Bombed; Moscow SMASHES Zelensky's 'POWERFUL WEAPONS'

Time of India

time14 hours ago

  • Time of India

Russia's FIERY Military Action After Putin City Bombed; Moscow SMASHES Zelensky's 'POWERFUL WEAPONS'

Russia said Sunday that a total of 93 Ukrainian unmanned aerial vehicles (UAVs) were taken down over various Russian regions overnight, including 19 over the Moscow Region. The drone attack triggered fires in Moscow suburbs, and reportedly caused some injuries. No further details were shared by Russian military, while Ukraine has not commented on the strike. Watch. Read More

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store