The US Department of Justice said that a 55-year-old doctor from Venezuela created and rented Jigsaw and Thanos ransomware to cybercriminals.
Moises Luis Zagala Gonzalez (Zagala) is a cardiologist with French and Venezuelan citizenship residing in Ciudad Bolivar, Venezuela. Zagala (aka Nosophoros, Aesculapius, and Nebuchadnezzar) also offered support to cybercriminals who bought the malware and shared profits earned after ransoming victims worldwide.
US Attorney Breon Peace stated that the multi-tasking doctor treated patients, created and named his cyber tool after death, profited from a global ransomware ecosystem in which he sold the tools for conducting ransomware attacks, trained the attackers about how to extort victims, and then boasted about successful attacks, including by malicious actors associated with the government of Iran.
Zagala is alleged to have not only created and sold ransomware products to hackers, but also trained them in their use.
Jigsaw ransomware includes a “Doomsday” counter that will delete a certain amount of files from the victims’ drives every hour until the ransom is paid, with an increasing number of files after each reset. Jigsaw is not really active now and a Jigsaw ransomware decryptor is available from Emsisoft.
Thanos ransomware is a Ransomware-as-a-Service (RaaS) operation advertised on Russian-speaking hacker forums. The malware allows affiliates to customize their own ransomware using a builder offered by the developer.
Zagala ran an affiliate program where cybercriminals would share their ransomware profits. He also licensed the Thanos malware using a licensing server he hosted in Charlotte, North Carolina.
According to DOJ press release, Zagala allegedly publicly discussed how his “clients” used his tools in ransomware attacks, “including by linking to a news story about an Iranian state-sponsored hacking group’s use of Thanos to attack Israeli companies.”
The law enforcement agents linked Zagala to the Thanos ransomware operation after interviewing one of his relatives who collected some of Zagala’s illicit proceeds from the ransomware operation using a PayPal account. He also showed them contact information stored in his phone that the defendant used to register some of the Thanos ransomware malicious infrastructure.
Zagala, if convicted, might face charges up to five years imprisonment for attempted computer intrusion and five years for conspiracy to commit computer intrusions.














Comments