An Interpol-led collaborative operation targeting phishing, banking malware, and ransomware attacks has led to the identification of 1,300 suspicious IP addresses and URLs.
The new operation named Synergia, took place between September to November 2023 and the law enforcement agencies from over 50 Interpol member countries have joined forces in this initiative.
Responding to the escalating threat of transnational cybercrime, the operation identified 1300 suspicious IP addresses or URLs associated with malicious activities.
During the operation, officers conducted house searches and seized servers and electronic devices. A total of 31 individuals were detained, and an additional 70 suspects were identified from Europe, South Sudan, and Zimbabwe.
The majority of command-and-control (C2) servers taken down were located in Europe. Hong Kong and Singapore police dismantled 153 and 86 servers, respectively, while South Sudan and Zimbabwe reported the highest takedowns on the African continent, leading to the arrest of four suspects. Kuwait collaborated closely with internet service providers (ISPs) to identify victims and mitigate impacts.
70% of the identified C2 servers have already been taken down, with the remaining under investigation.
Bernardo Pillot, assistant director of the Interpol Cybercrime Directorate stated that the results of this operation, achieved through the collective efforts of multiple countries and partners, show their unwavering commitment to safeguarding the digital space.
He added that by dismantling the infrastructure behind phishing, banking malware and ransomware attacks, they are one step closer to protecting the digital ecosystems and a safer, more secure online experience for all.
Interpol, along with its Gateway Partners Group-IB, Kaspersky, TrendMicro, Shadowserver and Ad hoc Partner Team Cymru, provided analysis and intelligence support throughout the operation.
Singapore-headquartered Group-IB, said it identified over 500 IP addresses hosting phishing resources and 1,900 IP addresses associated with ransomware, Trojans, and banking malware operations.
















Comments