Law enforcement agencies from 10 countries have taken down VPNLab.net, a VPN service provider which is used by ransomware operators and malware actors.
The disruptive joint action that was coordinated by Europol took place on January 17, 2022. Law enforcement actions in Germany, the Netherlands, Canada, the Czech Republic, France, Hungary, Latvia, Ukraine, the United States, and the United Kingdom were also involved.
15 servers used by the VPNLab.net service were seized and its main site was also taken down, so the platform is no longer available.
Cybercriminals use VPN (virtual private network) services to hide their real location and identity and obfuscate their online tracks by redirecting network traffic through multiple encryption tunnels.
VPNLab.net was one of the longest-standing and trustworthy services which was established in 2008 and offered OpenVPN-based technology and 2048-bit encryption for just $60/year.
Its servers were located in various countries, offering relative proximity to malicious actors worldwide.
Europol stated that law enforcement took an interest in the provider after multiple investigations uncovered criminals using the VPNLab.net service to perform illicit activities such as malware distribution.
In a separate press release, Ukrainian cybercrime police also detailed that this particular service has been used in at least 150 ransomware attacks.
The owners and operators of VPNLab.net are not yet identified, charged, or arrested. However, the law enforcement claims to have valuable evidence on that front now, a result of the servers’ seizure.
The customer data stored within them will also be scrutinized, so the police will likely identify more ransomware affiliates.
















Comments