International operation dismantles KillSec ransomware group | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The joint action against the ransomware group KillSec has resulted in three arrests, eight searches, and the seizure of servers, domains, devices, and assets linked to their activities.

The so-called Operation KillSwitch has brought together authorities from numerous countries and has been coordinated by Europol and Eurojust. Additionally, cybersecurity companies such as Bitdefender and Group-IB have also participated. DracoTeam, Bitdefender’s cybercrime unit, has provided resources, advice, and technical expertise during the investigation.

Five servers and 110 terabytes of data under police control

One of the main outcomes of the operation has been the seizure of KillSec’s technological infrastructure.

On September 30, authorities took control of their leak page and secured at least 110 terabytes of information to prevent further unauthorized access.

Throughout the investigation, five central servers also came under police control. Part of these systems were allegedly used to manage the group’s operations and store information obtained from attacked organizations.

Investigators also seized several domains used by KillSec. Those attempting to access them were met with an official notice informing them of the police action.

The international investigation is analyzing around 1,000 alleged attacks. Approximately 500 have achieved their goals, and there are more than 280 victims. Some have reportedly paid ransoms close to 500,000 euros via cryptocurrencies.

This is how KillSec extorted its victims

The group’s operation relied on finding vulnerabilities and insufficiently protected access points, especially in cloud storage services.

Once inside the systems, the attackers copied sensitive internal information and transferred it to infrastructures they controlled.

Subsequently, the extortion phase began. The affected organizations were identified on a leak page hosted on the dark web and received threats of publishing the stolen files if they refused to pay the ransom.

When negotiations failed, some of that information could become available for download.

Investigators have also determined that KillSec used artificial intelligence to build and maintain part of its ransomware infrastructure and locate potential targets.

A suspected administrator only 16 years old

The age of some of the suspects is one of the most striking aspects of the case. The investigation identified a 16-year-old teenager as the alleged administrator and main operator of KillSec.

Another suspect turned 18 in August 2026, although he was still a minor when some of the investigated crimes were committed.

Authorities have also identified individuals who allegedly performed negotiation and affiliation roles within the structure.

The various proceedings against KillSec began to converge after several countries investigated attacks attributed to the group since early 2025.

The investigations continue, and it is not ruled out that new individuals may be implicated as the vast amount of seized information is analyzed.

The scope of KillSwitch has required the collaboration of police and judicial authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States, in addition to Europol and Eurojust.

Alexandru Nicola Stoica, senior threat researcher at Bitdefender DracoTeam, highlights the extent of this cooperation: “This action demonstrates the power of collaboration between the public and private security sectors in dismantling criminal operations.”

The joint action against the ransomware group KillSec has resulted in three arrests, eight searches, and the seizure of servers, domains, devices, and assets linked to their activities.

The so-called Operation KillSwitch has brought together authorities from numerous countries and has been coordinated by Europol and Eurojust. Additionally, cybersecurity companies such as Bitdefender and Group-IB have also participated. DracoTeam, Bitdefender’s cybercrime unit, has provided resources, advice, and technical expertise during the investigation.

Five servers and 110 terabytes of data under police control

One of the main outcomes of the operation has been the seizure of KillSec’s technological infrastructure.

On September 30, authorities took control of their leak page and secured at least 110 terabytes of information to prevent further unauthorized access.

Throughout the investigation, five central servers also came under police control. Part of these systems were allegedly used to manage the group’s operations and store information obtained from attacked organizations.

Investigators also seized several domains used by KillSec. Those attempting to access them were met with an official notice informing them of the police action.

The international investigation is analyzing around 1,000 alleged attacks. Approximately 500 have achieved their goals, and there are more than 280 victims. Some have reportedly paid ransoms close to 500,000 euros via cryptocurrencies.

This is how KillSec extorted its victims

The group’s operation relied on finding vulnerabilities and insufficiently protected access points, especially in cloud storage services.

Once inside the systems, the attackers copied sensitive internal information and transferred it to infrastructures they controlled.

Subsequently, the extortion phase began. The affected organizations were identified on a leak page hosted on the dark web and received threats of publishing the stolen files if they refused to pay the ransom.

When negotiations failed, some of that information could become available for download.

Investigators have also determined that KillSec used artificial intelligence to build and maintain part of its ransomware infrastructure and locate potential targets.

A suspected administrator only 16 years old

The age of some of the suspects is one of the most striking aspects of the case. The investigation identified a 16-year-old teenager as the alleged administrator and main operator of KillSec.

Another suspect turned 18 in August 2026, although he was still a minor when some of the investigated crimes were committed.

Authorities have also identified individuals who allegedly performed negotiation and affiliation roles within the structure.

The various proceedings against KillSec began to converge after several countries investigated attacks attributed to the group since early 2025.

The investigations continue, and it is not ruled out that new individuals may be implicated as the vast amount of seized information is analyzed.

The scope of KillSwitch has required the collaboration of police and judicial authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States, in addition to Europol and Eurojust.

Alexandru Nicola Stoica, senior threat researcher at Bitdefender DracoTeam, highlights the extent of this cooperation: “This action demonstrates the power of collaboration between the public and private security sectors in dismantling criminal operations.”


——————————————————–


Click Here For The Original Source.

.........................