A recent operation by law enforcement in the US and abroad targeted the infrastructure of a Russian ransomware group linked to attacks on critical sectors.
Operation Against BlackSuit and Royal
On July 24, US law enforcement, in cooperation with international agencies, carried out an operation that seized four servers, nine domain names, and about $1 million in Bitcoin. The operation focused on infrastructure associated with BlackSuit and Royal groups.
Size of Demands and Consequences
According to reports, the group has demanded over $500 million in ransom since 2022, with one demand reaching as high as $60 million. The group has allegedly impacted more than 450 victims in the US, including hospitals and government agencies, collecting at least $370 million in illicit payments.
Global Coordination of Law Enforcement
This operation is part of a growing 'disruption-first' approach by US prosecutors, involving seizing servers and assets before gangs can move them or launch new attacks. Agencies involved included Homeland Security, the Secret Service, IRS Criminal Investigation, and the FBI.
The operation against BlackSuit and Royal highlights the importance of international cooperation in combating cybercrime and protecting critical infrastructures.