Technology

Trickbot hacker Arrested In South Korea While Fleeing

There is news from the supposed backers of the infamous TrickBot botnet, which for years distributed malicious code not only to companies but also to private individuals and caused great damage. A mastermind is said to have been arrested in Korea.

This is reported by the online magazine Bleeping Computer. It’s about a Russian developer who is believed to be part of the infamous TrickBot malware gang. He has now been arrested in South Korea while trying to leave the country, according to media reports. The TrickBot group is responsible for a wide variety of sophisticated malware. The target groups are both companies and private individuals, which has now become rather rare – many well-known Trojans are more specialized. The botnet, however, generally targets Windows and Linux devices, regardless of who is using them. TrickBot tries to gain access to the victim’s networks, steal data and use other malware such as ransomware.

Extradition to the USA

The broadcaster KBS reported that a Russian man was stuck in South Korea due to Covid-19 restrictions and that his passport expired as a result. After waiting for his passport to be renewed for over a year, he now tried to leave South Korea but was arrested at the airport due to an extradition request from the US.

He is charged with working as a developer for TrickBot while living in Russia in 2016. According to the broadcaster, the accused rejects this and claims that he did not know that he was working for criminals. He is currently trying to prevent his extradition to the USA with a lawyer. “If you extradite him to the United States, it will be very difficult to exercise his right to a defense, and there is a high possibility that he will be unduly punished,” argued the lawyer for the alleged TrickBot developer.

The TrickBot group is responsible for numerous malicious programs, including TrickBot, BazaLoader, BazaBackdoor, PowerTrick, and Anchor. All of these (malicious) tools are used to gain access to corporate networks, steal files and network credentials, and ultimately install blackmail software.

TrickBot Gang

It is believed that both the Ryuk and Conti ransomware operations are also carried out by the TrickBot gang. A few months ago, the news made the rounds that the network had been paralyzed – but that turned out to be a mistake. TrickBot is still active.

Recent Posts

Spider-Man: Brand New Day is now the highest-grossing film in the series

Just three weeks after its theatrical release, Tom Holland's fourth solo outing, Spider-Man: Brand New…

4 days ago

Nvidia AI chip found in new Russian cruise missile

Ukrainian intelligence has discovered an AI chip from Nvidia in a Russian cruise missile. The…

4 days ago

Wake Island is back: Battlefield 6 is free to play this week

From August 18th, the multiplayer shooter Battlefield 6 can be played free of charge for…

4 days ago

Bilibili: Chinese YouTube begins its overseas expansion

The Chinese video platform Bilibili wants to push more strongly into the international market and…

4 days ago

Users are canceling their Claude subscriptions because of new AI flagging

AI company Anthropic has introduced invisible watermarks for its text generator Claude. In order to…

4 days ago

ChatGPT goes Windows Recall: AI now records Mac actions

With the new Computer History for ChatGPT under MacOS, OpenAI promises an intelligent helper that…

4 days ago