\r\n\u00a9 2022<\/p>\r\n
Any use of Europol\u2019s logo requires prior written consent.<\/p>\r\n","footer-bottom-second":"
Europol is committed to user privacy. All personal data collected by Europol are processed in accordance with the provisions of Regulation (EU) 2018\/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45\/2001 and Decision No 1247\/2002\/EC. We will handle all the information received from you confidentially. Confidentiality implies that your personal data will be disclosed only to authorised personnel of Europol. However, it may be necessary for the future investigation to inform the national competent authority concerned about the content of the information received from you and\/or your identity.<\/p>\r\n"},"terms":{"tags":[],"languages":[{"id":362,"title":"Bulgarian"},{"id":579,"title":"Gaelic"},{"id":574,"title":"Icelandic"},{"id":557,"title":"Luxembourgish"},{"id":580,"title":"Macedonian"},{"id":515,"title":"Norwegian"},{"id":516,"title":"Russian"},{"id":517,"title":"Ukranian"},{"id":363,"title":"Spanish"},{"id":364,"title":"Czech"},{"id":365,"title":"Danish"},{"id":366,"title":"German"},{"id":367,"title":"Estonian"},{"id":368,"title":"Greek"},{"id":369,"title":"English"},{"id":370,"title":"French"},{"id":371,"title":"Irish"},{"id":372,"title":"Italian"},{"id":373,"title":"Latvian"},{"id":374,"title":"Lithuanian"},{"id":375,"title":"Hungarian"},{"id":376,"title":"Maltese"},{"id":377,"title":"Dutch"},{"id":378,"title":"Polish"},{"id":379,"title":"Portuguese"},{"id":380,"title":"Romanian"},{"id":381,"title":"Slovak"},{"id":382,"title":"Slovene"},{"id":383,"title":"Finnish"},{"id":384,"title":"Swedish"},{"id":385,"title":"Croatian"},{"id":386,"title":"Other"}]}},"NodeLoader":{"node":{"id":2560,"type":"news","title":"Five arrested for spreading ransomware throughout Europe and US","alias":"\/media-press\/newsroom\/news\/five-arrested-for-spreading-ransomware-throughout-europe-and-us","published":1513767601,"navigation":{"previous":"\/media-press\/newsroom\/news\/eleven-arrests-in-successful-hit-against-sports-corruption-in-multiple-european-member-states","next":"\/media-press\/newsroom\/news\/illegal-trade-in-endangered-species-29-arrests-and-over-2000-animals-seized-in-international-operation-sukazu"},"updated":1514797201,"body":"
During the last week, Romanian authorities have arrested three individuals who are suspected of infecting computer systems by spreading the CTB-Locker (Curve-Tor-Bitcoin Locker) malware - a form of file-encrypting ransomware. Two other suspects from the same criminal group were arrested in Bucharest in a parallel ransomware investigation linked to the US. As a result of the searches in Romania, investigators seized a significant amount of hard drives, laptops, external storage devices, cryptocurrency mining devices and numerous documents. The criminal group is being prosecuted for unauthorised computer access, serious hindering of a computer system, misuse of devices with the intent of committing cybercrimes and blackmail.<\/p>\n\n In early 2017, the Romanian authorities received detailed information from the Dutch High Tech Crime Unit and other authorities that a group of Romanian nationals were involved in sending spam messages. This spam was specifically drafted to look like it was sent from well-known companies in countries like Italy, the Netherlands and the UK. The intention of the spam messages was to infect computer systems and encrypt their data with the CTB-Locker ransomware aka Critroni. Each email had an attachment, often in the form of an archived invoice, which contained a malicious file. Once this attachment was opened on a Windows system, the malware encrypted files on the infected device.<\/p>\n\n CTB-Locker was first detected in 2014 and was one of the first ransomware variants to use Tor to hide its command and control infrastructure. It targets almost all versions of Windows, including XP, Vista, 7 and 8. Once infected, all documents, photos, music, videos, etc. on the device are encrypted asymmetrically, which makes it very difficult to decrypt the files without the private key in possession of the criminals, which might be released when victims pay the ransom.<\/p>\n\n As a result of the law enforcement activities, more than 170 victims from several European countries have been identified to date; all filed complaints and provided evidence that will help with the prosecution of the suspects.<\/p>\n\n
\n
\nDuring this law enforcement operation called \"Bakovia\", six houses were searched in Romania as a result of a joint investigation carried out by the Romanian Police (Service for Combating Cybercrime), the Romanian and Dutch public prosecutor\u2019s office, the Dutch National Police (NHTCU), the UK\u2019s National Crime Agency, the US FBI with the support of Europol\u2019s European Cybercrime Centre (EC3)<\/a> and the Joint Cybercrime Action Taskforce (J-CAT)<\/a>.<\/p>\n\n