Leader of Qakbot Malware Conspiracy Indicted for Involvement in Global Ransomware Scheme
俄罗斯男子Rustam Gallyamov被指控领导一个网络犯罪集团开发并部署了Qakbot恶意软件,并利用该恶意软件建立了一个僵尸网络来传播多种勒索软件。美国司法部已没收其超过2400万美元的加密货币,并与多国合作成功破坏了该恶意软件网络。尽管如此,Gallyamov及其同伙仍继续通过“垃圾炸弹”攻击和其他新型勒索软件实施犯罪活动。 2025-5-28 14:16:53 Author: flashpoint.io(查看原文) 阅读量:16 收藏

“A federal indictment unsealed today charges Rustam Rafailevich Gallyamov, 48, of Moscow, Russia, with leading a group of cyber criminals who developed and deployed the Qakbot malware. In connection with the charges, the Justice Department filed today a civil forfeiture complaint against over $24 million in cryptocurrency seized from Gallyamov over the course of the investigation. These actions are the latest step in an ongoing multinational effort by the United States, France, Germany, the Netherlands, Denmark, the United Kingdom, and Canada to combat cybercrime.”

“According to court documents, Gallyamov developed, deployed, and controlled the Qakbot malware beginning in 2008. From 2019 onward, Gallyamov allegedly used the Qakbot malware to infect thousands of victim computers around the world in order to establish a network, or ‘botnet,’ of infected computers. As alleged, once Gallyamov gained access to victim computers, he provided access to co-conspirators who infected the computers with ransomware, including Prolock, Dopplepaymer, Egregor, REvil, Conti, Name Locker, Black Basta, and Cactus. In exchange, Gallyamov was allegedly paid a portion of the ransoms received from ransomware victims.”

“The announcement of charges today is the latest step taken by the Justice Department against the Qakbot conspiracy. In August 2023, a U.S.-led multinational operation disrupted the Qakbot botnet and malware. At that time, the Justice Department announced the seizure of illicit proceeds from Gallyamov, including over 170 bitcoin and over $4 million of USDT and USDC tokens.”

“According to the indictment, after the disruption and takedown of the Qakbot botnet, Gallyamov and his co-conspirators continued their criminal activities. Instead of a botnet, they allegedly used different tactics, including ‘spam bomb’ attacks on victim companies, where co-conspirators would trick employees at those victim companies into granting access to computer systems. The indictment alleges that Gallyamov orchestrated spam bomb attacks against victims in the United States as recently as January 2025. It also alleges that Gallyamov and his co-conspirators deployed Black Basta and Cactus ransomware on victim computers.” (Source: US Department of Justice)

Begin your free trial today.


文章来源: https://flashpoint.io/blog/leader-of-qakbot-malware-conspiracy-indicted-for-involvement-in-global-ransomware-scheme/
如有侵权请联系:admin#unsafe.sh