字号 ·· | 护眼
theregister

青少年涉嫌运营KillSec勒索软件团伙,警方缴获服务器并逮捕三人Teen suspected of running KillSec ransomware group as cops seize servers, arrest three

点「原文对照」整页切到原文,或双击某段只看那段的原文。

警方怀疑一名16岁少年是KillSec勒索软件组织的主要操控者,该组织与全球约1000起疑似袭击事件有关。当局于周四宣布,一次国际行动已查封该组织的基础设施,并临时逮捕三人。由德国主导的“KillSwitch行动”将该团伙的泄露网站替换为警方查封公告。现有信息极其零散。欧洲刑警组织表示,这名16岁少年“疑似是该团伙的主要操控者”,但并未明确说明此人是否已被逮捕。

Police suspect a 16-year-old was the main operator of KillSec, a ransomware group linked to around 1,000 suspected attacks worldwide. Authorities announced on Thursday that an international operation had seized the group's infrastructure and made three provisional arrests. The German-led Operation KillSwitch replaced the crew's leak site with a police seizure notice. The available information is incredibly fragmented. Europol said the 16-year-old was "the group's suspected main operator," but did not explicitly say this person was arrested.

西班牙警方宣布逮捕了一名“未成年人”,此人是一名居住在西班牙的罗马尼亚公民,但警方没有公开将此次逮捕与欧洲刑警组织提到的16岁少年联系起来。美国司法部称,英国警方已逮捕荷兰国民Fouad Eltibrizi,美国司法部已就其涉嫌在美国和波多黎各实施网络犯罪提出指控,并正寻求将其引渡。Eltibrizi是官员唯一公开点名的嫌疑人。

Spanish police announced the arrest of a "minor," a Romanian national residing in Spain, but did not publicly link this arrest to the 16-year-old mentioned by Europol. The US Department of Justice (DoJ) said UK police had arrested Dutch national Fouad Eltibrizi, whom it has charged over alleged cybercrimes in the US and Puerto Rico. It is seeking his extradition. Eltibrizi is the only suspect officials have publicly named.

欧洲刑警组织向The表示,据称他是KillSec的谈判人员之一。当局尚未公布那名疑似16岁操控者的身份。罗马尼亚警方(Poliția Română)称,一名24岁人士曾协助于2023年10月建立KillSec,但其他当局将该团伙的成立时间定为2024年。罗马尼亚警方的声明没有说明此人是否已被逮捕。官员另行向The证实,一名20多岁的罗马尼亚公民因涉嫌充当KillSec关联成员,在罗马尼亚被捕。

Europol told The he was allegedly one of KillSec's negotiators. Authorities have not named the suspected 16-year-old operator. Romanian police (Poliția Română) said a 24-year-old helped establish KillSec in October 2023, although other authorities date the group's formation to 2024. Their statement did not specify whether that person was arrested. Officials separately confirmed to The that a Romanian national in his twenties was arrested in Romania on suspicion of acting as a KillSec affiliate.

欧洲刑警组织还确认了一名疑似开发者,此人于8月刚满18岁,在部分涉嫌犯罪行为发生时仍是未成年人。西班牙警方提到一名与该案有关、目前仍在接受调查但未被逮捕的女子。协同突袭行动于9月30日进行,相关调查始于2025年初。欧洲和美国的10家警察机构参与了此次行动,警员突袭了希腊、罗马尼亚、西班牙和英国的八处房产。

Europol also identified a suspected developer who turned 18 in August and was a minor when some of the alleged offenses were committed. Spanish police referenced a woman who remains under investigation in connection to the case, but was not arrested. The coordinated raids took place on September 30, following investigations that began in early 2025. Ten police agencies from Europe and the US took part, with officers raiding eight properties across Greece, Romania, Spain, and the UK.

西班牙警方称,警员突袭了阿利坎特一家酒店内的一处住宅和一间办公室,与此同时,罗马尼亚警方搜查了四所住宅。希腊和英国均未公布其参与此次行动的相关信息。当局已控制KillSec泄露网站上的至少110 TB数据,防止其遭到进一步非法访问。调查人员正在检查查获的设备和数据,以确定受害者、攻击事件和嫌疑人,并追查该团伙的犯罪收益。

Spanish police said officers raided a home and an office in an Alicante hotel, while Poliția Română searched four homes. Neither Greece nor the UK has released information about their involvement in the operation. Authorities secured at least 110 TB of data on KillSec's leak site against further unauthorized access. Investigators are examining seized devices and data to identify victims, attacks, and suspects, and trace the group's criminal proceeds.

调查期间,警方接管了五台中央服务器,这些服务器用于管理该团伙的活动并存储受害者数据。网络安全企业Bitdefender和Group-IB也协助了调查。KillSec采用双重勒索手段,通过加密受害者的系统,并威胁在受害者不付款的情况下公布窃取的数据。Group-IB近日将KillSec——又称“Kill Security”和“k1llsec”——列入其2025年亚太地区、拉丁美洲和中东勒索软件团伙十大榜单。

Over the course of the investigation, police took control of five central servers used to manage the group's activities and store victims' data. Security shops Bitdefender and Group-IB also supported the investigation. KillSec uses double extortion, encrypting victims' systems and threatening to publish stolen data unless they pay. Group-IB recently included KillSec, also referred to as "Kill Security" and "k1llsec," in its 2025 top 10 rankings for ransomware groups operating in APAC, LATAM, and the Middle East.

该公司研究人员表示,KillSec最常以金融服务和医疗机构为目标,但也曾攻击政府机构和大企业。Group-IB称,KillSec还以5000至50万美元不等的价格出售窃取的数据。Group-IB首席执行官德米特里·沃尔科夫表示:“服务器几周内就能更换,但搭建该平台并批准每一次攻击的人却无法更换。查明这些人的身份,并协助执法部门将其绳之以法,才能让一次查封从‘暂时停摆’变为‘彻底终结’。”

The company's researchers said KillSec most commonly preyed on financial services and healthcare organizations, but was known to attack government entities and large enterprises. Group-IB said KillSec also offered stolen data for sale at prices ranging from $5,000 to $500,000. "Servers can be replaced in weeks; the people who build the platform and approve every attack cannot," said Group-IB CEO Dmitry Volkov. "Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end."

KillSec最初提供的是一款Windows加密工具,后来又推出一个能够加密VMware ESXi主机、删除数据、关闭虚拟机并移除恢复点的版本。®

KillSec initially offered a Windows encryptor before adding a version capable of encrypting VMware ESXi hosts, deleting data, shutting down VMs, and removing recovery points. ®