Posts in Category
Court Documents

United Kingdom National Charged in Connection with Multiple Cyber Attacks, Including on Critical Infrastructure
A complaint filed in the District of New Jersey charges Thalha Jubair, a United Kingdom national, with conspiracies to commit computer fraud, wire fraud, and money laundering, in relation to at least 120 computer network intrusions and extortion involving 47 U.S. entities.

Justice Department Announces Arrest of Prolific Chinese State-Sponsored Contract Hacker
Xu Zewei and his co-defendant, PRC national Zhang Yu, are charged for their involvement in computer intrusions between February 2020 and June 2021, including the indiscriminate HAFNIUM computer intrusion campaign that compromised thousands of computers worldwide, including in the U.S.

Serial Hacker “IntelBroker” Charged For Causing $25 Million In Damages To Victims
Kai West, a British national, is charged with operating the “IntelBroker” online identity, infiltrating victim computer networks, stealing data, selling it, and causing millions in damages to dozens of victims around the world.

Leader of Qakbot Malware Conspiracy Indicted for Involvement in Global Ransomware Scheme
"A federal indictment unsealed today charges Rustam Rafailevich Gallyamov, 48, of Moscow, Russia, with leading a group of cyber criminals who developed and deployed the Qakbot malware. In connection with the charges, the Justice…

16 Defendants Federally Charged in Connection with DanaBot Malware Scheme That Infected Computers Worldwide
A federal grand jury indictment and criminal complaint unsealed today charge 16 defendants who allegedly developed and deployed the DanaBot malware which a Russia-based cybercrime organization controlled and deployed, infecting more than 300,000 victim computers around the world, facilitated fraud and ransomware, and caused at least $50 million in damage.

Justice Department Charges 12 Chinese Contract Hackers and Law Enforcement Officers in Global Computer Intrusion Campaigns
According to court documents, the MPS and MSS employed an extensive network of private companies and contractors in China to hack and steal information in a manner that obscured the PRC government’s involvement.

Phobos Ransomware Affiliates Arrested in Coordinated International Disruption
The Justice Department has unsealed criminal charges against Roman Berezhnoy, 33, and Egor Nikolaevich Glebov, 39, both Russian nationals, who allegedly operated a cybercrime group using the Phobos ransomware that victimized more than 1,000 public and private entities in the United States and around the world and received over $16 million in ransom payments.

Cracked and Nulled Marketplaces Disrupted in International Cyber Operation
The marketplaces has been selling stolen login credentials, hacking tools, and servers for hosting malware and stolen data, affecting at least 17M victims in the U.S.

Justice Department and FBI Conduct International Operation to Delete Malware Used by China-Backed Hackers
According to court documents, the PRC government paid the Mustang Panda group to, among other computer intrusion services, develop this specific version of PlugX. Since at least 2014, Mustang Panda hackers then infiltrated thousands of computer systems in campaigns targeting U.S. victims, as well as European and Asian governments and businesses, and Chinese dissident groups.

United States Charges Dual Russian and Israeli National as Developer of LockBit Ransomware Group
In August, Rostislav Panev, 51, a dual Russian and Israeli national, was arrested in Israel pursuant to a U.S. provisional arrest request with a view towards extradition to the United States. Panev is currently in custody in Israel pending extradition on the charges in the superseding complaint.

Fourteen North Korean Nationals Indicted for Carrying Out Multi-Year Fraudulent Information Technology Worker Scheme and Related Extortions
The conspirators, who worked for DPRK-controlled companies Yanbian Silverstar and Volasys Silverstar, located in the People’s Republic of China (PRC) and the Russian Federation (Russia), respectively, conspired to use false, stolen, and borrowed identities of U.S. and other persons to conceal their North Korean identities and foreign locations and obtain employment as remote information technology (IT) workers for U.S. companies and nonprofit organizations.

China-Based Hacker Charged for Conspiring to Develop and Deploy Malware That Exploited Tens of Thousands of Firewalls Worldwide
The malware that exploited the vulnerability discovered by Guan was designed to steal information from infected computers and to encrypt files on them if a victim attempted to remediate the infection. In total, Guan and his co-conspirators infected approximately 81,000 firewall devices worldwide, including a firewall device used by an agency of the United States.