GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to both this project and an event.

Spanish police arrest 16-year-old suspected of operating crypto ransomware KillSec

Odaily News: Spanish police have arrested a 16-year-old Romanian national in Alicante on suspicion of being the administrator and primary operator of the KillSec ransomware group. Europol stated that law enforcement agencies have seized control of the group's servers and leak site, and preserved at least 110 TB of stolen data.The operation involved searches at 8 residences across Spain, Greece, Romania, and the United Kingdom, investigating approximately 1,000 suspected attacks worldwide, of which about 500 have been confirmed successful. Two other suspects in their 20s were arrested in the UK and Romania respectively, while a Dutch national residing in the UK was indicted and arrested in Puerto Rico, awaiting extradition.KillSec has been active since around 2024, often demanding ransoms in cryptocurrency and carrying out double extortion through encrypted servers and threats to publish stolen data. Investigators are tracing the group's proceeds, including cryptocurrency; Europol's European Cybercrime Centre provided cryptocurrency tracing and digital forensics support. (Decrypt)

Trezor customer data exposed due to ShipMonk security breach, affecting users in 7 countries

Odaily News: Bitcoin News posted on X platform that Trezor stated its customer data was exposed due to a security breach at logistics provider ShipMonk. Customers who received orders within 90 days before August 8 in the United States, United Kingdom, Sweden, Colombia, Brazil, Italy, or Portugal may be affected. The exposed data includes full names, shipping addresses, phone numbers, email addresses, and order numbers. Trezor stated that its systems were not compromised and devices remain secure, but reminded affected customers to beware of sophisticated phishing attacks leveraging the leaked information.

EU Sanctions "Most Prolific Ransomware Operator" Stern, Linked to Over $300 Million in Ransom Payments

the United States, the European Union, and the United Kingdom have jointly announced sanctions against a group of individuals involved in state-sponsored hacking organizations, cybercriminal groups, and their infrastructure providers. The targets are accused of causing billions of dollars in losses to global enterprises, critical infrastructure, and government agencies. Among them, the most notable is the EU's sanction against Russian cybercriminal Vitaly Nikolayevich Kovalev, also known as "Stern." The EU identified Stern as one of the core managers of the notorious Trickbot Group ransomware syndicate, which is behind high-risk ransomware variants such as Conti ransomware and Ryuk.On-chain analysis shows that wallet addresses linked to Stern have collectively received over $300 million in ransom payments, potentially making him the most prolific ransomware operator ever identified.According to the analysis, the $300 million figure represents only Stern's personal gains, while the total illicit income of the Trickbot Group could be significantly higher. On-chain fund flows indicate that Stern had transactional ties with multiple ransomware ecosystems, including Ryuk, Conti, Diavol, Karakurt, Royal, and Quantum.The investigation reveals that Stern played a role similar to a "CEO" within the Trickbot organization, responsible for budget management, personnel recruitment, infrastructure procurement, and attack planning. (Chainalysis)

Grinex Ceases Operations, Potentially Delivering a Heavy Blow to Russia’s Sanctions-Evasion Shadow Financial System

According to DL News, Russian cryptocurrency exchange Grinex announced last Wednesday that it would cease operations after suffering a cyberattack that resulted in the theft of over 1 billion rubles—approximately $13 million. The report states that Grinex had processed nearly $100 billion in trading volume for the sanctioned stablecoin A7A5 in 2025. Its shutdown is expected to weaken Russian companies’ ability to convert rubles into usable international currencies and deliver a severe blow to Russia’s shadow financial system designed to circumvent sanctions. Grinex was viewed as the successor to Garantex, which had previously been sanctioned and shut down. Both Grinex and Old Vector—the issuer of A7A5—were sanctioned in August 2025 by the United States, the European Union, and the United Kingdom.