Gang – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Wed, 13 Aug 2025 04:14:48 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Gang – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 US takes down sites, seizes $1M from crypto ransomware gang BlackSuit https://earlybirdsinvest.com/us-takes-down-sites-seizes-1m-from-crypto-ransomware-gang-blacksuit/ https://earlybirdsinvest.com/us-takes-down-sites-seizes-1m-from-crypto-ransomware-gang-blacksuit/#respond Wed, 13 Aug 2025 04:14:48 +0000 https://earlybirdsinvest.com/us-takes-down-sites-seizes-1m-from-crypto-ransomware-gang-blacksuit/

The US has seized servers, domain names, and around $1 million in crypto assets from the ransomware group BlackSuit.

The Justice Department said on Monday that multiple US and international law enforcement agencies conducted an operation against the BlackSuit ransomware groups in late July.

The operation included the unsealing of a warrant for the seizure of cryptocurrency valued at just over $1 million, at the time of the seizure, it reported. 

“Disrupting ransomware infrastructure is not only about taking down servers, it’s about dismantling the entire ecosystem that enables cybercriminals to operate with impunity,” added Michael Prado, Deputy Assistant Director at the Homeland Security Investigations Cyber Crimes Center.

Blacksuit is a spinoff of the Royal ransomware gang and has operated since at least 2023, with the latest seizure coming amid other actions the US has taken against ransomware groups, such as sanctioning the ransomware hosting provider Aeza Group in July.

The Justice Department said the takedown was led by the US Department of Homeland Security’s Homeland Security Investigations with help from the Secret Service, the IRS and the FBI, along with law enforcement from the UK, Germany, Ireland, France, Canada, Ukraine, and Lithuania.

Coordinated ransomware attacks 

The Justice Department said the ransomware group persistently targeted critical infrastructure across sectors, including healthcare, government facilities, manufacturing, and commercial facilities. Victims are typically forced to pay ransoms in Bitcoin (BTC) through darknet websites.

Since 2022, BlackSuit has compromised over 450 known victims in the US and has received more than $370 million in ransom payments, it added.

The ransomware schemes used double-extortion tactics such as encrypting victims’ systems while threatening to leak stolen data to further coerce payment, the DOJ stated. 

Sample of BlackSuit ransom demand. Source: SentinelOne 

“The BlackSuit ransomware gang’s persistent targeting of US critical infrastructure represents a serious threat to US public safety,” said Assistant Attorney General for National Security John Eisenberg.

Bitcoin ransom seized 

In 2023, a victim paid a ransom of 49.3 BTC, worth around $1.4 million at the time, to decrypt their data. 

A portion of the ransom payment, the seized $1 million, was repeatedly deposited and withdrawn from a crypto exchange account until the funds were frozen by the exchange in early 2024, it reported, though it did not name the exchange. 

Related: US sanctions crypto wallet tied to ransomware, infostealer host

Ransom demands have typically ranged from approximately $1 million to $10 million in BTC, and the largest ransom demanded by BlackSuit actors was $60 million, according to the Cybersecurity and Infrastructure Security Agency.

Crypto ransomware successors crop up

In July, the Dallas, Texas, FBI announced the seizure of 20 BTC valued at around $2.4 million from a cryptocurrency address belonging to a prominent member of the Chaos ransomware group.

Last week, analysts at TRM Labs investigated how a new ransomware group called Embargo may have emerged as a successor operation to BlackCat, which launders proceeds through crypto accounts. Approximately $18.8 million worth remains dormant in unattributed wallets, it revealed. 

Magazine: Scottie Pippen says Michael Saylor warned him about Satoshi chatter

]]> https://earlybirdsinvest.com/us-takes-down-sites-seizes-1m-from-crypto-ransomware-gang-blacksuit/feed/ 0 52931 Sensata Technologies says personal data stolen by ransomware gang https://earlybirdsinvest.com/sensata-technologies-says-personal-data-stolen-by-ransomware-gang/ https://earlybirdsinvest.com/sensata-technologies-says-personal-data-stolen-by-ransomware-gang/#respond Mon, 09 Jun 2025 17:23:52 +0000 https://earlybirdsinvest.com/sensata-technologies-says-personal-data-stolen-by-ransomware-gang/

Sensata

Sensata Technologies is warning former and current employees it suffered a data breach after concluding an investigation into an April ransomware attack.

Sensata is a global industrial tech firm specializing in mission‑critical sensors, controls, and electrical protection systems. It serves the automotive, aerospace, and defense industries, among others, and has an annual revenue of over $4 billion.

In April, the company filed an 8-K filing with the U.S. Securities and Exchange Commission (SEC), disclosing that it suffered a ransomware attack on Sunday, April 6, which also included data theft.

The cybersecurity incident impacted Sensata’s shipping, manufacturing, and other business operations.

Although preliminary investigations confirmed data exfiltration, the exact data that had been stolen and the scope of the exposure weren’t determined at the time.

Subsequent investigations into the incident supported by an external expert showed that the ransomware actors breached Sensata’s network on March 28, 2025.

“The evidence showed that there was unauthorized activity in our network between March 28, 2025, and April 6, 2025,” reads the notice sent to impacted persons.

“During that time, an unauthorized actor viewed and obtained files from our network. We conducted a careful review of the files and, on May 23, 2025, determined that one or more of them may have contained your information.”

The company is now notifying an undisclosed number of impacted individuals that the following data was stolen:

  • Full name
  • Address
  • Social Security Number (SSN)
  • Driver’s license number
  • State ID card number
  • Passport number
  • Financial account information
  • Payment card information
  • Medical information
  • Health insurance information
  • Date of birth

The breach impacts current and former Sensata employees and their dependents, with the exposed information varying per individual.

The firm enclosed instructions in the letter on enrolling in one year of credit monitoring and identity theft protection service.

BleepingComputer has reached out to Sensata to specify the scope of the data breach and the number of impacted individuals, but we have not received a response by publication.

As of writing, no ransomware groups have taken responsibility for the attack at Sensata.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/sensata-technologies-says-personal-data-stolen-by-ransomware-gang/feed/ 0 41063
Vietnamese Arrests Crypto Gang Behind $394 Million Matrix Chain Scam https://earlybirdsinvest.com/vietnamese-arrests-crypto-gang-behind-394-million-matrix-chain-scam/ https://earlybirdsinvest.com/vietnamese-arrests-crypto-gang-behind-394-million-matrix-chain-scam/#respond Thu, 29 May 2025 06:40:54 +0000 https://earlybirdsinvest.com/vietnamese-arrests-crypto-gang-behind-394-million-matrix-chain-scam/

On May 28, five suspects accused of running a large-scale crypto scheme called Matrix Chain were arrested by authorities in Vietnam.

The group is believed to have tricked thousands of people into handing over close to $394 million, or around 10 trillion VND.

The Ministry of Public Security stated that officers worked for 200 days to uncover how the group operated. The suspects, four men and one woman born between 1980 and 1991, were detained after police searched their homes and workplaces.

How to Avoid Rug Pulls in Crypto? (5 Ways Explained)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

According to investigators, the group promoted Matrix Chain to earn high returns and easy commissions. New users were told to pay just 1 USDT
USDT


$0.9949

to access the platform’s software.

The scam was reported to have operated across three major regions in Vietnam. Around 40% of the money brought in went to people tasked with finding new users, while 5% was used for marketing. The rest was reportedly spent on expensive items and property.

Police believe the main suspect behind the operation is Nguyen Quoc Hung. In 2023, he allegedly paid $20,000 to anonymous developers on Telegram to build the Matrix Chain platform. He and another person then managed a wallet containing 100 million MTC tokens.

Matrix Chain had over 185,000 registered accounts, with users sending in a total of 394.2 million USDT through SafePal wallets.

Authorities stated that they have frozen related accounts and seized property linked to the suspects.

On May 22, authorities in the United States and across Europe carried out an international operation, known as Operation RapTor. What is the target? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/vietnamese-arrests-crypto-gang-behind-394-million-matrix-chain-scam/feed/ 0 38909
Paris Family Fights Off Masked Gang in Crypto-Linked Kidnapping Attempt https://earlybirdsinvest.com/paris-family-fights-off-masked-gang-in-crypto-linked-kidnapping-attempt/ https://earlybirdsinvest.com/paris-family-fights-off-masked-gang-in-crypto-linked-kidnapping-attempt/#respond Sun, 18 May 2025 03:00:37 +0000 https://earlybirdsinvest.com/paris-family-fights-off-masked-gang-in-crypto-linked-kidnapping-attempt/

A masked gang tried to abduct the daughter and young grandson of a crypto company executive in Paris, but the attackers fled empty-handed after a violent struggle.

This incident is part of a trend of violent cases targeting individuals connected to the crypto industry in France.

Crypto Exec’s Family Targeted in Attack

According to a BBC report, the attack happened around 8:20 a.m. in the city’s 11th district and was captured on video by an onlooker. Local media revealed that the woman and her husband were getting out of their car with their child when three men jumped out of a white van and tried to pull them away.

The couple fought back, which resulted in the husband being hit several times on the head while trying to protect his family. Meanwhile, the wife managed to grab a gun from one of the culprits and threw it into the street. Police later confirmed the weapon was a replica air gun.

Despite the busy street and children on their way to school nearby, passers-by hesitated to intervene at first. However, as more people began to react, the attackers abandoned the attempt and ran back to the van, where a fourth person was waiting inside.

As the culprits drove away, one witness threw a fire extinguisher at the vehicle. Following the incident, the family was taken to a hospital and treated for minor injuries.

Police sources confirmed that the woman is the daughter of a crypto company boss. AFP said the victims are relatives of the co-founder of French Bitcoin exchange Paymium. The Paris police unit that handles armed robbery is now investigating the incident.

A Series of Crypto-Related Kidnappings

This development follows a similar case just over a week earlier, where the father of a crypto millionaire was kidnapped in another part of Paris while walking his dog. In this instance, the abductee was held for ransom.  After being in captivity for three days, he was released with one of his fingers cut off. Several people have been arrested in connection with the case.

Another high-profile incident happened in January when David Balland, co-founder of crypto wallet firm Ledger, and his wife were taken at their home in central France, with the culprits demanding a 10 million euro ransom for their release.

While they were later rescued, Balland was also found missing a finger. Around the same time, rumors spread about another abduction involving Ledger’s other co-founder, Eric Larchevêque. However, these claims were later denied by French media.

Authorities have not confirmed whether the incidents are connected, but all victims involved had some link to crypto.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/paris-family-fights-off-masked-gang-in-crypto-linked-kidnapping-attempt/feed/ 0 36845
Teen Crypto Gang Blew $263 Million on Private Jets, Clubs, and Luxury Cars https://earlybirdsinvest.com/teen-crypto-gang-blew-263-million-on-private-jets-clubs-and-luxury-cars/ https://earlybirdsinvest.com/teen-crypto-gang-blew-263-million-on-private-jets-clubs-and-luxury-cars/#respond Fri, 16 May 2025 08:02:26 +0000 https://earlybirdsinvest.com/teen-crypto-gang-blew-263-million-on-private-jets-clubs-and-luxury-cars/

A group of young people is facing federal charges for allegedly stealing over $263 million in cryptocurrency and spending the money on expensive cars, parties, and high-end items.

US authorities announced charges against 12 new individuals on May 15, naming Malone Lam in a four-count indictment.

Most of the accused are between 18 and 21 years old. Some are American citizens, while others are foreign nationals. Two of them are believed to be in Dubai, and a few are known only by their online usernames.

What is an Automated Market Maker in Crypto? (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The charges include conspiracy under racketeering laws, wire fraud, and money laundering. One member, John Tucker Desmond, is accused of destroying evidence to interfere with the investigation.

According to court documents, the group formed around October 2023 after meeting on gaming platforms. Each person had a different role—some hacked databases, others pretended to be support staff to trick victims, and a few helped move the stolen crypto into cash.

The group reportedly used a range of tools to hide their activity, including VPNs, coin mixers, and fake companies. They used the money for personal use, booking private jet flights, buying at least 28 luxury cars, renting expensive homes, and spending large amounts at clubs. Some of the cash was hidden inside stuffed toys during transport.

Authorities also reported that Lam continued to give instructions to others while in custody, including telling someone to deliver luxury items to his partner. The investigation is ongoing, with help from FBI teams in Los Angeles and Miami.

On May 14, authorities in Europe arrested 17 people for operating a crypto-based network that laundered over $23 million. How did the case unfold? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/teen-crypto-gang-blew-263-million-on-private-jets-clubs-and-luxury-cars/feed/ 0 36521
Crypto Exchange CEO’s Daughter and Grandson Narrowly Escape Kidnap Attempt by Armed Gang in France: Report https://earlybirdsinvest.com/crypto-exchange-ceos-daughter-and-grandson-narrowly-escape-kidnap-attempt-by-armed-gang-in-france-report/ https://earlybirdsinvest.com/crypto-exchange-ceos-daughter-and-grandson-narrowly-escape-kidnap-attempt-by-armed-gang-in-france-report/#respond Thu, 15 May 2025 10:02:10 +0000 https://earlybirdsinvest.com/crypto-exchange-ceos-daughter-and-grandson-narrowly-escape-kidnap-attempt-by-armed-gang-in-france-report/

Armed assailants have reportedly attempted to kidnap the daughter and grandson of a crypto exchange executive in France.

The news television network France 24 reports that four masked men attacked a couple and their child in broad daylight in Paris on Tuesday.

Video footage shows that three of the perpetrators jumped out of a white delivery van to force the woman and her child into the vehicle. They also beat the woman’s partner, who tried to intervene.

But the woman, the daughter of France-based crypto exchange platform Paymium CEO and co-founder Pierre Noizat, resisted. She grabbed one of the attackers’ handguns and threw it away.

The commotion caught the attention of passersby who tried to help, including one man who brought out a fire extinguisher. The attackers eventually ended up fleeing in their waiting vehicle.

The victims sustained injuries and were taken to the hospital.

The attack follows a series of incidents targeting crypto entrepreneurs in France. In January, kidnappers abducted crypto wallet firm Ledger co-founder David Balland and his wife and demanded a large ransom in cryptocurrency. The police managed to rescue the couple and the suspects, including the alleged mastermind, are now detained.

Last month, masked men also kidnapped the father of a crypto millionaire in the French capital and demanded ransom. The police were able to locate the place of detention and freed the man during a raid.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Generated Image: Midjourney

]]>
https://earlybirdsinvest.com/crypto-exchange-ceos-daughter-and-grandson-narrowly-escape-kidnap-attempt-by-armed-gang-in-france-report/feed/ 0 36334
Interlock ransomware gang pushes fake IT tools in ClickFix attacks https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/ https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/#respond Fri, 18 Apr 2025 19:56:08 +0000 https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/

Hacker

The Interlock ransomware gang now uses ClickFix attacks that impersonate IT tools to breach corporate networks and deploy file-encrypting malware on devices.

ClickFix is a social engineering tactic where victims are tricked into executing dangerous PowerShell commands on their systems to supposedly fix an error or verify themselves, resulting in the installation of malware.

Though this isn’t the first time ClickFix has been linked to ransomware infections, confirmation about Interlock shows an increasing trend in these types of threat actors utilizing the tactic.

Interlock is a ransomware operation launched in late September 2024, targeting FreeBSD servers and Windows systems.

Interlock is not believed to operate as a ransomware-as-a-service model. Still, it maintains a data leak portal on the dark web to increase pressure on victims, demanding payments ranging from hundreds of thousands of dollars to millions.

From ClickFix to ransomware

In the past, Interlock utilized fake browser and VPN client updates to install malware and breach networks.

According to Sekoia researchers, the Interlock ransomware gang began utilizing ClickFix attacks in January 2025.

Interlock used at least four URLs to host fake CAPTCHA prompts that tell visitors to execute a command on their computer to verify themselves and download a promoted tool.

The researchers say they detected the malicious captcha on four different sites, mimicking Microsoft or Advanced IP Scanner portals:

  • microsoft-msteams[.]com/additional-check.html
  • microstteams[.]com/additional-check.html
  • ecologilives[.]com/additional-check.html
  • advanceipscaner[.]com/additional-check.html

However, only the site impersonating Advanced IP Scanner, a popular IP scanning tool commonly used by IT staff, led to downloading a malicious installer.

Page hosting Interlock's ClickFix bait
Page hosting Interlock’s ClickFix bait
Source: Sekoia

Clicking the ‘Fix it’ button copies the malicious PowerShell command to the victim’s clipboard. If executed in a command prompt or Windows Run dialog, it will download a 36MB PyInstaller payload.

At the same time, the legitimate AdvanceIPScanner website opens in a browser window to reduce suspicion.

The malicious payload installs a legitimate copy of the software it pretends to be and simultaneously executes an embedded PowerShell script that runs in a hidden window.

This script registers a Run key in Windows Registry for persistence and then collects and exfiltrates system info including OS version, user privilege level, running processes, and available drives.

Sekoia has observed the command and control (C2) responding with various payloads, including LummaStealer, BerserkStealer, keyloggers, and the Interlock RAT.

The latter is a simple trojan that can be dynamically configured, supporting file exfiltration, shell command execution, and running malicious DLLs.

Commands Interlock RAT supports
Commands Interlock RAT supports
Source: Sekoia

After the initial compromise and RAT deployment, Interlock operators used stolen credentials to move laterally via RDP, while Sekoia also saw PuTTY, AnyDesk, and LogMeIn used in some attacks.

The last step before the ransomware execution is data exfiltration, with the stolen files uploaded to attacker-controlled Azure Blobs.

The Windows variant of Interlock is set (via a scheduled task) to run daily at 08:00 PM, but thanks to file extension-based filtering, this doesn’t cause multiple layers of encryption but serves as a redundancy measure.

Sekoia also reports that the ransom note has evolved, too, with the latest versions focusing more on the legal aspect of the data breach and the regulatory consequences if stolen data is made public.

Interlock's latest ransom note
Interlock’s latest ransom note
Source: BleepingComputer

ClickFix attacks have now been adopted by a wide range of threat actors, including other ransomware gangs and North Korean hackers.

Last month, Sekoia discovered that the infamous Lazarus North Korean hacking group was using ClickFix attacks targeting job seekers in the cryptocurrency industry.

]]>
https://earlybirdsinvest.com/interlock-ransomware-gang-pushes-fake-it-tools-in-clickfix-attacks/feed/ 0 31552
Tren de Aragua: Venezuelan prison gang Trump claims is “toughest” in world, explained https://earlybirdsinvest.com/tren-de-aragua-venezuelan-prison-gang-trump-claims-is-toughest-in-world-explained/ https://earlybirdsinvest.com/tren-de-aragua-venezuelan-prison-gang-trump-claims-is-toughest-in-world-explained/#respond Mon, 17 Mar 2025 17:13:07 +0000 https://earlybirdsinvest.com/tren-de-aragua-venezuelan-prison-gang-trump-claims-is-toughest-in-world-explained/

Over the weekend, the stakes of the Trump administration’s deportation efforts reached a new level after the White House invoked an 18th-century legal authority to expand its powers. A federal judge attempted to block the removal of hundreds of alleged gang members, but the administration carried on with the deportations, arguing the order came too late.

More than 200 Venezuelan immigrants, which the White House accused of being members of a Venezuelan gang, were flown — along with some suspected members of a Salvadoran gang — from the US to a supermax prison in El Salvador on Saturday. The White House claims the court order didn’t apply to this flight because it was already over international waters on its way to El Salvador by the time it was put into effect. The Trump administration says it welcomes a coming legal fight over its expanded immigration authority.

President Donald Trump has previously noted his hope of using these powers to target “known or suspected” members of a particular criminal organization: the “Tren de Aragua,” a Venezuela-based gang he frequently mentioned when talking about immigration and crime on the campaign trail. And earlier this year Trump took the steps to designate the group as a foreign “terrorist” organization invading the US. He’s now applying that law against this Venezuelan group.

“Tren de Araguasprang out of Venezuela in the 2010s and has been accused of setting up and running human trafficking and extortion rings in neighboring Colombia, Chile, and Peru. As border crossings, asylum claims, and migration from Latin America in general picked up since the pandemic, the group has been of particular interest for Trump and immigration hawks.

As Trump and his allies have tried to portray undocumented immigration as a threat to public safety, they’ve repeatedly highlighted the Tren de Aragua (or TdA)’s criminal activity in the US and abroad. That emphasis has coincided with TdA’s post-pandemic expansion in the US, though it’s deeply unclear how many TdA members are here — and how powerful the gang actually is.

Still, a few high-profile incidents — in which the perpetrators were accused of being TdA members — have caught Trump’s attention, and they’ve been a consistent focus of conservative media, immigration critics, and local law enforcement agencies. Those include a high-profile forced entry in an apartment complex in Aurora, Colorado, that Trump seized upon last summer and highlighted during his debate against former Vice President Kamala Harris.

But not much is actually known about the group, how it operates, or the extent of its reach within the United States. Still, that hasn’t stopped officials, politicians, and commentators from using real instances of crime and violence to paint a picture of a dangerous migrant “invasion.”

Trump himself did that on Tuesday night, referencing the murder of a 12-year-old Texan girl in the Houston area. Two undocumented Venezuelan men were eventually charged with her murder, and both are accused of being members of the gang — which Trump called the “toughest gang, they say, in the world, known as Tren de Aragua.”

Whether the Tren de Aragua is the toughest in the world is debatable. But back in Venezuela and along the routes that migrants follow to get to the US, it has contributed to insecurity, instability, and violence.

What is the Tren de Aragua?

While we don’t know a lot about the state of the organization in the United States right now, a lot is known about the group’s origins. The Tren de Aragua has its roots in a trade union that was formed to build a railroad in 2005, during Venezuelan dictator Hugo Chavez’s tenure. According to researchers who have studied the group’s rise and local journalists, it morphed from being a railway workers’ group into an organization that embezzled funds and extorted contractors during that construction process. The project ended up falling apart in 2011, but by then the group had morphed itself into a larger criminal organization, being led out of the infamous Tocoron prison, a detention center in the state of Aragua, Venezuela, that had been overtaken by inmates.

It was there that the groups’ current leader joined the group, and eventually led the Tren de Aragua to expand its extortion, local drug dealing, and human trafficking into other Venezuelan states, and eventually into Colombia, Chile, and Peru. It’s no coincidence that the TdA’s rise happened around the start of Venezuela’s economic crisis in 2014 and in 2017. Rising poverty, collapsing social safety nets, and political repression created opportunities for both recruitment and targets of extortion, human trafficking, and sexual exploitation among the very migrants and refugees fleeing instability back home.

After establishing itself in those neighboring countries since 2018 — and with the rise in Venezuelan refugees and other South American migrants in the United States since the pandemic, reports of people with alleged ties to the group have steadily increased in the US. Scores of news and government reports have tied supposed gang members to murders, sex trafficking and exploitation cases, and petty crime. Immigration officials, meanwhile, frequently label undocumented immigrants who have been arrested and are in the process of being deported as alleged TdA members.

But it’s hard to prove these associations, Charles Larratt-Smith, an assistant professor of security studies and researcher on transnational migration at the University of Texas at El Paso, told me. Unlike in the cases of other transnational criminal groups — like Mexico’s drug cartels or MS-13, the Salvadoran gang born in Los Angeles that ended up wreaking havoc in El Salvador after its members were deported or removed from the US — there’s no evidence or intelligence sharing between the US and Venezuela that can help identify members, and no straightforward hierarchy or line of command within this network. Essentially anyone can claim or be accused of being a member of the group, since there’s no reliable way to cross-reference membership, or for the group itself to hold its members accountable. Even the tattoos and other symbols used to try to identify group members can be inconsistent. And the group’s original base of operations, the Tocoron prison, has since been retaken by the Venezuelan government, and its leader has disappeared.

In other words, the group’s influence, reach, and actual power may have been exaggerated over the years. “If you’re comparing those organizations to the Tren de Aragua, the comparison is farcical,” Larratt-Smith said. The shadowy group just doesn’t have the same means, resources, organization, or power to compete with the groups various American government and Homeland Security officials have compared it to.

And yet both Trump’s and Biden’s administrations have argued they pose enough of a threat to warrant federal responses, Just last year, the Biden administration levied sanctions against the group and designated it as a transnational criminal organization. And in January, the Trump White House went one step further, reclassifying it as a foreign terrorist organization.

So while there are places where the group’s presence is better established, like in New York City, the shadowy description of the group also serves other political purposes.

For Larratt-Smith, the fear the Tren de Aragua, and its presence in the US, inspires in people serves to both justify the Trump administration’s crackdown on immigration in general, and helps to muddy the differences between those actual TdA gang members in the US and any Venezuelan immigrants who commit crimes in the US or may have criminal records back home. “It’s a useful signifier for Venezuelan criminality — and that does exist, you would have to be naïve or delusional to say otherwise — but it’s disproportionately publicized compared to acts of criminality committed by American citizens, because it fits this broader [anti-immigrant] narrative,” he told me.

Update, March 17 at 10:35 am ET: This story was originally published on March 7, 2025, and has been updated to include the Trump administration’s latest Tren de Aragua-related immigration actions.

]]>
https://earlybirdsinvest.com/tren-de-aragua-venezuelan-prison-gang-trump-claims-is-toughest-in-world-explained/feed/ 0 25683
Australian IVF giant Genea breached by Termite ransomware gang https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/ https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/#respond Wed, 26 Feb 2025 15:16:27 +0000 https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/

Genea

​The Termite ransomware gang has claimed responsibility for breaching and stealing sensitive healthcare data belonging to Genea patients, one of Australia’s largest fertility services providers.

The IVF (in vitro fertilization) provider has been operating since 1986 (when it was known as Sydney IVF). It offers a wide range of services, including fertility treatments, tests, genetic services, preservation options, and donor programs, in 22 fertility clinics in New South Wales, South Australia, Western Australia, Melbourne, Canberra, and Queensland.

According to Australia’s national broadcaster, Genea and two other companies (Monash IVF and Virtus) account for over 80% of the industry’s total revenue in the country.

Genea first revealed last Wednesday it was investigated a “cyber incident” after detecting “suspicious activity” on its network. In an updated statement issued today, the fertility services giant confirmed the attackers stole data from its systems, which was later published online.

The company said it obtained a court-ordered injunction to prevent the leaked data from being shared by others, and it’s also working with the Office of the Australian Information Commissioner and the Australian Cyber Security Centre to investigate an incident.

The redacted court order reveals that the threat actors breached Genea’s network on January 31, 2025, through a Citrix server. Subsequently, they gained access to the company’s primary file server, domain controller, backup program, and BabySentry primary patient management system. Two weeks later, on February 14, the attackers exfiltrated 940.7GB of data from Genea’s compromised systems to a DigitalOcean cloud server under their control.

The ongoing investigation also discovered that Genea’s compromised patient management systems contained the following types of personal and health data, with the exposed information varying for each affected individual: 

  • Full names, emails, addresses, phone numbers, date of birth, emergency contacts, and next of kin,
  • Medicare card numbers, private health insurance details, Defence DA numbers, medical record numbers, patient numbers,
  • Medical history, diagnoses and treatments, medications and prescriptions, patient health questionnaire, pathology and diagnostic test results, notes from doctors and specialists, appointment details, and schedules.

“At this stage there is no evidence that any financial information such as credit card details or bank account numbers have been impacted by this incident,” Genea added.

“The investigation is however ongoing, and we will keep you updated of any relevant further findings should they come to light.”

A Genea spokesperson has not replied to several requests for comment since the company disclosed the breach on February 19.

Breach claimed by Termite ransomware

While Genea didn’t attribute the attack to a specific threat group or cybercrime operation, the Termite ransomware gang claimed responsibility on Monday.

In a new entry on their dark web leak site, they said they stole roughly 700GB of data and leaked screenshots of identification documents and patients’ files allegedly stolen from Genea’s network.

“We have ~700gb of data from company’s servers such as confidential, personal data of clients,” the threat actors claim.

Genea entry on Termite's leak site
Genea entry on Termite’s leak site (BleepingComputer)

Termite is a ransomware operation that surfaced in mid-October, according to threat intelligence company Cyjax, and has since listed 18 victims on its dark web portal from all over the world and various industry sectors.

In December, the ransomware gang also claimed to have breached the network of Arizona-based service (SaaS) provider Blue Yonder. This worldwide supply chain software provider has over 3,000 customers, including high-profile companies such as Microsoft, Renault, Bayer, Tesco, Lenovo, DHL, 3M, Ace Hardware, Procter & Gamble, Carlsberg, Dole, Wallgreens, Western Digital, and 7-Eleven.

Like other ransomware gangs, the Termite cybercrime group is involved in data theft, extortion, and encryption attacks. According to cybersecurity firm Trend Micro, they’re using a version of the Babuk encryptor leaked in September 2021 and are known to drop a “How To Restore Your Files.txt” ransom note on the victims’ encrypted systems.

Trend Micro also added that Termite’s ransomware encryptor is still likely a work in progress, as it will terminate prematurely due to a code execution flaw.

]]>
https://earlybirdsinvest.com/australian-ivf-giant-genea-breached-by-termite-ransomware-gang/feed/ 0 22007
Gang Hits Crypto ATMs, Steals Collectible Cards—Police Shut Them Down https://earlybirdsinvest.com/gang-hits-crypto-atms-steals-collectible-cards-police-shut-them-down/ https://earlybirdsinvest.com/gang-hits-crypto-atms-steals-collectible-cards-police-shut-them-down/#respond Mon, 17 Feb 2025 22:22:04 +0000 https://earlybirdsinvest.com/gang-hits-crypto-atms-steals-collectible-cards-police-shut-them-down/

Australian authorities have arrested four people linked to a series of burglaries targeting cryptocurrency ATMs and collectible card stores across Melbourne’s northwest.

In a February 17 statement, officers seized around 50,000 AUD ($31,800) worth of trading cards and several firearms in the process.

According to Victoria Police’s North West Metro Regional Crime Squad, the group is accused of breaking into ATMs in Brunswick, Hoppers Crossing, Bentleigh, Werribee, and Vermont.

Non-custodial Wallet: Why Do You Need It Right NOW

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Authorities also believe they raided trading card stores in Epping, Moonee Ponds, and Eumemmerring since mid-January, stealing cards from brands like Yu-Gi-Oh, Pokémon, Dragon Ball Z, AFL, and NBA.

Search warrants were carried out in Reservoir, Coburg North, Greensborough, and South Morang, leading to the seizure of five firearms, ammunition, around 100 stolen car keys, and a pill press machine.

Two men are facing multiple charges. A 32-year-old from Epping faces charges related to commercial burglary, vehicle theft, and methamphetamine possession. Meanwhile, a 37-year-old from Reservoir has been charged with 14 counts of burglary and firearm offenses.

Police say the suspects may be connected to a larger Middle Eastern crime syndicate that directed their activities. Two other individuals, aged 33 and 46, were questioned and later released as the investigation continues.

Detective Inspector Patrick Watkinson credited the arrests to cooperation between law enforcement, the trading card community, and business owners.

Meanwhile, an international investigation exposed a $100 million crypto laundering network. How? Read the full story.

]]>
https://earlybirdsinvest.com/gang-hits-crypto-atms-steals-collectible-cards-police-shut-them-down/feed/ 0 20155