Cyber Hacking News

FIN7 hacking group member gets 5-year sentence in the US

0

A Ukrainian national has been sentenced to 5 years imprisonment in the United States for his criminal work as a member of the FIN7 hacking group.

The US Department of Justice (DoJ) announced the sentencing of Denys Iarmak for working as a FIN7 penetration tester.

FIN7, also known as Carbanak, is a cybercriminal group that focuses on financial theft. It has been active since at least 2015, and tends to target the retail and banking sector through Business Email Compromise (BEC) scams, attacks against point-of-sale (PoS) systems, and supply chain compromise.

The malware used by the group includes backdoors, information stealers, Trojans, RDP access modules, and even malicious USB drives that are physically mailed to unsuspecting businesses. They are constantly evolving its tactics and improving its toolkit.

According to Blueliv researchers, FIN7 is one of the top threats to today’s financial sector. It is estimates that at least $1 billion in damages has been done by the group to US organizations and consumers.

32 year old Iarmak worked as a pentester for the group and he was responsible for managing network intrusions.

Among his tasks was creating intrusion ‘projects’ in JIRA to track cyberattacks, including the initial access, surveillance progress, and data theft. Group members could comment on each project and offer each other advice.

Iarmak was apprehended and arrested in Bangkok, Thailand, in 2019, but he was later extradited to the US in 2020.

He was charged and pleaded guilty to one count of conspiracy to commit wire fraud and one count of conspiracy to commit computer hacking.

The DoJ began arresting FIN7 members in 2018 and so far three have been sentenced in the United States.

Image Credits : BankInfoSecurity

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

US disrupts Russia-linked Cyclops Blink botnet

Previous article

FFDroider, a new information-stealing malware targets users in the wild

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *