The FBI, the UK’s National Crime Agency, and partners in several countries announced the disruption of GameOver Zeus, a botnet used to steal banking credentials, and the CryptoLocker ransomware. The operation was known as Operation Tovar.
What happened
- GameOver Zeus was estimated to have infected over a million computers worldwide and caused losses of more than 100 million US dollars.
- CryptoLocker encrypted victims’ files and demanded a ransom, and was often spread to machines already infected with GameOver Zeus.
- US prosecutors charged Evgeniy Bogachev of Anapa, Russia, as the alleged leader of the group; he remains wanted.
- In the UK, the NCA warned the public they had a two-week window to protect their computers.
Why it mattered
It was one of the first large-scale takedowns of a peer-to-peer botnet and brought ransomware to mainstream public attention.
Lessons for organisations
Organisations should keep regular offline or immutable backups so ransomware cannot hold data hostage, and use endpoint protection and email filtering to block the malware that delivers it. Cyber Essentials covers many of these basic controls.
Sources: FBI, The Register
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.