In Moscow, at the request of Interpol, a suspect was detained who is associated with one of the most powerful hacker groups

Carding Forum

Professional
Messages
2,788
Reaction score
1,176
Points
113
In Moscow, at the request of Interpol, a suspect was detained, whom German security forces associate with one of the most powerful hacker groups. In Germany, he is accused of four counts.

According to the "Database", 37-year-old Fyodor A. was detained in the morning of July 15 in a house on Danilovskaya Embankment. Fedor was taken into custody — in the Interpol database, the notification of the man is marked with a "red corner". It requires the law enforcement authorities of the Interpol member States to immediately arrest the person being sought for the purpose of subsequent extradition (if it is allowed by the court).

In Germany, Fedor is suspected of several articles at once: organizing criminal and terrorist communities, computer sabotage, violating the secrecy of correspondence and extortion. Fedor is suspected in connection with the hacker group Trickbot, also known as Wizard Spider. On its account dozens of hacks and extortion. As the media wrote, Trickbot created one of the most dangerous banking viruses — thanks to hacks in Germany alone, Trickbot members managed to earn more than 8 million euros.
 
Russian media, with reference to the Baza telegram channel, report that on the morning of July 15, 37-year-old Fyodor A., allegedly associated with the Trickbot group, was detained in Moscow.

"Fedor was taken into custody — in the Interpol database, the notification of the man is marked with a "red corner". It requires the law enforcement authorities of the Interpol member States to immediately arrest the person being sought for the purpose of subsequent extradition (if it is allowed by the court).

In Germany, Fedor is suspected of several articles at once: organizing criminal and terrorist communities, computer sabotage, violating the secrecy of correspondence and extortion. Fedor is suspected in connection with the hacker group Trickbot, also known as Wizard Spider. On its account dozens of hacks and extortion. As the media wrote, Trickbot created one of the most dangerous banking viruses — thanks to hacks in Germany alone, Trickbot members managed to earn more than 8 million euros."

If the information is correct, then we may be talking about Fyodor Alexandrovich Andreev, born in 1986. At the end of May, the German Federal Criminal Police Department put Andreev and seven other Russians on the wanted list as part of Europol's international operation Operation Endgame. The operation was aimed at destroying the infrastructure of cybercriminals and seizing illegally obtained funds. Europol called the joint actions of law enforcement officers the largest operation against botnets (IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee and Trickbot), more than 100 servers were seized, more than 2000 domains were confiscated, and arrests were made in Armenia (one suspect) and Ukraine (three).

About Andreev, German law enforcement officers report that initially he could have been a malware tester, and then took the position of a team leader in the team.

Western countries have been struggling with TrickBot for a long time: in 2020, it was reported that the US Cyber Command conducted attacks on botnet operators, and Microsoft, on the basis of trademark protection, achieved a legal opportunity to disrupt the operation of certain elements of the botnet infrastructure. In 2021, as part of a short period of activation of Russian-American contacts on information security, the US authorities sent information to Russia, including via TrickBot. According to American requests, suspects of involvement in the group's activities are arrested and extradited to the United States: in 2021, Russian Vladimir Dunaev was extradited from the Republic of Korea, two years later he pleaded guilty, and in January of this year he was sentenced to 5 years and 4 months in prison. In early 2023, the United States and the United Kingdom imposed sanctions (against seven alleged Trickbot participants from Russia.

I don't recall any previous arrests of suspects with ties to the group in Russia. If the information about Fedor A. is confirmed, and the detention will have consequences, then this story deserves serious attention.

-----

47e006c594.png


• ANDREEV: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/AF/Sachverhalt.html?nn=230514

• BRAGIN: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/BA/Fahndung_BA.html?nn=230514

• CHEREPANOV: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/CA/Fahndung_CA.html?nn=230514

• CHERESHNEV: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/CN/Fahndung_CN.html?nn=230514

• GRUBER: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/GA/Fahndung_GA.html?nn=230514

• POLYAK: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/PS/Fahndung_PS.html?nn=230514

• TESMAN: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/TG/Fahndung_TG.html?nn=230514

• KUCHEROV: https://www.bka.de/DE/IhreSicherhei...ersonen/Endgame/KO/Fahndung_KO.html?nn=230514

• Source: https://www.bka.de/DE/IhreSicherhei...game/_Endgame_Uebersicht/Uebersicht_node.html

• Source: https://www.europol.europa.eu/media...gainst-botnets-hits-dropper-malware-ecosystem
 
Top