Cyberattack News

Authorities Dismantled SugarLocker Ransomware Group

Russian authorities have successfully dismantled a notorious ransomware gang known as SugarLocker, arresting three of its alleged members.

The group, which masqueraded as a legitimate tech company named Shtazi-IT, specialized in the development of various digital services, including landing pages, mobile apps, and online stores.

This operation marks a critical step in the global fight against ransomware, highlighting the increasing effectiveness of law enforcement in tracking and neutralizing cyber threats.

The Arrests and Investigation

The arrests were the culmination of a collaborative investigation involving F.A.C.C.T., a Russia-based cybersecurity firm, and other authorities.

Document
Analyse Shopisticated Malware with ANY.RUN

Try ANY.RUN Yourself with a 14-day Free Trial

More than 300,000 analysts use ANY.RUN is a malware analysis sandbox worldwide. Join the community to conduct in-depth investigations into the top threats and collect detailed reports on their behavior..

F.A.C.C.T. played a pivotal role in uncovering the activities of the SugarLocker gang. The individuals apprehended were known by the nicknames blade_runner, GustaveDore, and JimJones.

They face charges related to the creation, use, and distribution of malicious computer programs, with potential prison sentences of up to four years if found guilty.

The investigation remains ongoing, with authorities continuing to gather evidence and explore the full extent of the group’s activities.

SugarLocker’s Operations

SugarLocker has been active since at least 2021, operating under the ransomware-as-a-service (RaaS) model. This approach involves offering malicious tools for a fee or a share of the ransom payments collected by criminals.

The group’s malware primarily targeted victims through the Remote Desktop Protocol (RDP), allowing for remote access and control over computers.

Notably, SugarLocker pledged not to attack Eastern European countries, with the exception of the Baltic States and Poland and did not operate a data leak site, making it challenging to identify their victims.

The group’s profit-sharing model was particularly lucrative, receiving 30% of its customers’ profits or 10% if they exceeded $5 million.

This financial motivation underscores the purely business-oriented nature of their operations, as stated in their ransom note: “It’s just a business. We absolutely do not care about you and your deals… If you do not cooperate with our service, for us, it does not matter. But you will lose your time and data.”

The dismantling of the SugarLocker ransomware group is a significant victory for cybersecurity and law enforcement agencies worldwide.

It sends a strong message to cybercriminals about the increasing risks of engaging in ransomware activities and the growing capabilities of authorities to track and prosecute them.

This operation also highlights the importance of international collaboration and the role of private cybersecurity firms in combating cyber threats.

As the investigation continues, the cybersecurity community will be watching closely for further developments and insights into the tactics and strategies employed by ransomware gangs.

The success of this operation may also encourage more proactive measures and cooperation between different countries and organizations to address the global challenge of ransomware.

You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.

Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago