operators – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Tue, 08 Jul 2025 06:30:22 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 operators – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 War Wallets Exposed: 60 Crypto Operators Under Ukraine’s Gun https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/ https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/#respond Tue, 08 Jul 2025 06:30:22 +0000 https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

In a defiant move, Ukraine strikes at crypto routes fueling Russia’s war machine. The war-torn European country has unleashed a dramatic wave of sanctions designed to choke off the digital pipelines that have been fueling Russia’s military campaign.

President Volodymyr Zelenskyy signed Decree No. 465/2025, effectively freezing the assets and banning operations of 60 crypto firms—55 based in Russia and five scattered across Cyprus, Kazakhstan and the UAE.

This sweeping action is meant to send a strong message: crypto won’t be a safe haven for money that bankrolls conflict.

Sanctions Span Exchange Miners And Issuers

According to the decree, five crypto exchanges are accused of moving funds for sanctioned Russian entities. Nineteen mining operations have been caught processing coins linked to sanctioned individuals.

Seventeen platforms that issue digital assets already under US restrictions are now blocked in Ukraine. Another 19 companies—from makers of payment terminals to brokers arranging international transfers—face asset freezes and activity bans.

Ukraine didn’t stop at companies. The sanctions list also names 73 individuals, all Russian citizens, including high‑ranking central bank officials.

Based on reports from Ukraine’s National Security and Defense Council, these measures will be shared with allies like the EU and the US. That way, they can mirror the bans and tighten the grip on every channel Russia uses.

Total crypto market cap currently at $3.3 trillion. Chart: TradingView

Coordination With Allies Aims To Close Loopholes

Vladyslav Vlasiuk, Ukraine’s commissioner for Sanctions Policy, said Kyiv will urge its partners to adopt matching rules. The goal is to close every loophole Russia uses to fund its military.

Zelenskyy revealed that one single firm moved “several billion dollars” since January to support Russia’s military‑industrial complex. That figure shows why digital channels have become critical for sanctioned players.

New Stablecoin Highlights Growing Risks

Based on reports by the Financial Times and the Centre for Information Resilience, Russia’s crypto use is on the rise. A new stablecoin called A7A5, pegged to the ruble, moved over $9 billion in just four months on the Grinex exchange.

More than 12 billion A7A5 tokens now float in circulation, backed by roughly $156 million in reserves held at the US‑sanctioned Promsvyazbank. Only a few wallets handled most of that volume, showing how a small group can steer vast sums.

Meanwhile, five non‑Russian companies also made the list: Token Trust Holdings Limited in Cyprus, EXMO RBC Limited in Kazakhstan, AWX Solutions and Crypto Explorer DMCC in the UAE, and Bitpapa IC FZC in the UAE.

All five are already under US restrictions. Their inclusion highlights how sanctions evasion often relies on a global network of service providers.

Featured image from Unsplash, chart from TradingView

Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

]]>
https://earlybirdsinvest.com/war-wallets-exposed-60-crypto-operators-under-ukraines-gun/feed/ 0 46407
DanaBot malware operators exposed via C2 bug added in 2022 https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/ https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/#respond Wed, 11 Jun 2025 06:50:54 +0000 https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/

Spying

A vulnerability in the DanaBot malware operation introduced in June 2022 update led to the identification, indictment, and dismantling of their operations in a recent law enforcement action.

DanaBot is a malware-as-a-service (MaaS) platform active from 2018 through 2025, used for banking fraud, credential theft, remote access, and distributed denial of service (DDoS) attacks.

Zscaler’s ThreatLabz researchers who discovered the vulnerability, dubbed ‘DanaBleed,’ explain that a memory leak allowed them to gain a deep peak into the malware’s internal operations and the people behind it.

Leveraging the flaw to collect valuable intelligence on the cybercriminals enabled an international law enforcement action named ‘Operation Endgame’ to take DanaBot infrastructure offline and indict 16 members of the threat group.

DanaBleed

The DanaBleed flaw was introduced in June 2022 with DataBot version 2380, which added a new command and control (C2) protocol.

A weakness in the new protocol’s logic was in the mechanism that generated the C2 server’s responses to clients, which was supposed to include randomly generated padding bytes but didn’t initialize newly allocated memory for these.

Zscaler researchers collected and analyzed a large number of C2 responses that, due to the memory leak bug, contained leftover data fragments from the server’s memory.

This exposure is analogous to the HeartBleed problem discovered in 2014, impacting the ubiquitous OpenSSL software.

As a result of DanaBleed, a broad array of private data was exposed to the researchers over time, including:

  • Threat actor details (usernames, IP addresses)
  • Backend infrastructure (C2 server IPs/domains)
  • Victim data (IP addresses, credentials, exfiltrated info)
  • Malware changelogs
  • Private cryptographic keys
  • SQL queries and debug logs
  • HTML and web interface snippets from the C2 dashboard

For over three years, DanaBot operated in a compromised mode without its developers or clients ever realizing they were being exposed to security researchers.

This allowed targeted law enforcement action when enough data had been collected.

Leaked HTML data on the C2 server responses
Leaked HTML data on the C2 server responses
Source: Zscaler

Although DanaBot’s core team in Russia was merely indicted and not arrested, the seizure of critical C2 servers, 650 domains, and nearly $4,000,000 in cryptocurrency has effectively neutralized the threat for now.

It is not unlikely that the threat actors attempt to return to cybercrime operations in the future, but reduced trust from the hackers’ community will be a significant obstacle for them.

Tines Needle

Patching used to mean complex scripts, long hours, and endless fire drills. Not anymore.

In this new guide, Tines breaks down how modern IT orgs are leveling up with automation. Patch faster, reduce overhead, and focus on strategic work — no complex scripts required.

]]>
https://earlybirdsinvest.com/danabot-malware-operators-exposed-via-c2-bug-added-in-2022/feed/ 0 41367
Sanctioned Russian Crypto Exchange Garantex Seized, Operators Charged With Money Laundering https://earlybirdsinvest.com/sanctioned-russian-crypto-exchange-garantex-seized-operators-charged-with-money-laundering/ https://earlybirdsinvest.com/sanctioned-russian-crypto-exchange-garantex-seized-operators-charged-with-money-laundering/#respond Fri, 07 Mar 2025 18:50:46 +0000 https://earlybirdsinvest.com/sanctioned-russian-crypto-exchange-garantex-seized-operators-charged-with-money-laundering/

Garantex, a Russian crypto exchange popular with ransomware gangs and darknet markets, has been taken down in an international law enforcement operation, according to a Friday announcement from the U.S. Department of Justice (DOJ).

On Thursday, a coalition of law enforcement agencies from the U.S., Germany and Finland seized Garantex’s domains and servers, and froze nearly $28 million in crypto tied to the exchange with the help of stablecoin issuer Tether.

The U.S. Treasury’s Office of Foreign Asset Control (OFAC) sanctioned Garantex in 2022, accusing the exchange of knowingly facilitating money laundering for ransomware actors, including Conti and Black Basta, and darknet markets like Hydra, which, before its 2022 shut down, was once the largest darknet market in the world.

The sanctions had little to no effect on Garantex – according to data from blockchain sleuthing firm Elliptic, which aided the U.S. in its investigation, the exchange processed more than $60 billion in crypto transactions after being sanctioned. In total, the exchange has transacted over $96 billion.

According to court documents, Garantex collected virtually no know-your-customer (KYC) information about its clients, allowing criminals to use its services unchecked, and accounts were registered to customers using names like “Drug,” “hacker,” “taliban,” “Cashout, cleancoins” and “God.”

In addition to ransomware actors and darknet markets, Garantex’s clientele allegedly included North Korea’s state-sanctioned hacking squad, the Lazarus Group, which was behind the massive $1.5 billion Bybit heist last month, as well as Russian oligarchs, who used the service to evade international sanctions tied to the war in Ukraine. Sophisticated international sanctions evasion companies, like TGR Group, which cater to Russian elites, have been tied to Garantex.

Following the seizure of Garantex’s servers and domains, two of its operators have been criminally charged in the U.S. for their connections to the exchange.

Lithuanian national and Russian resident Aleksej Besciokov, 46, has been charged with money laundering conspiracy, conspiracy to violate sanctions, and conspiracy to operate an unlicensed money transmitting business. Aleksandr Mira Serda, 40, a Russian citizen currently residing in the United Arab Emirates, has been charged with money laundering conspiracy.

]]>
https://earlybirdsinvest.com/sanctioned-russian-crypto-exchange-garantex-seized-operators-charged-with-money-laundering/feed/ 0 23838
US indicts 8Base ransomware operators for Phobos encryption attacks https://earlybirdsinvest.com/us-indicts-8base-ransomware-operators-for-phobos-encryption-attacks/ https://earlybirdsinvest.com/us-indicts-8base-ransomware-operators-for-phobos-encryption-attacks/#respond Tue, 11 Feb 2025 15:48:24 +0000 https://earlybirdsinvest.com/us-indicts-8base-ransomware-operators-for-phobos-encryption-attacks/

US indicts 8Base ransomware operators for Phobos encryption attacks

The U.S. Justice Department announced the names of two Phobos ransomware affiliates arrested yesterday in Thailand, charging them on 11 counts due to their involvement in more than a thousand cyberattacks.

The two men, Roman Berezhnoy (33) and Egor Nikolaevich Glebov (39) are both Russian citizens, active in the ransomware space between May 2019 and at least October 2024.

The DoJ says Berezhnoy and Glebov were the operators of the “8Base” and “Affiliate 2803” platforms, both deploying the Phobos ransomware strain in attacks.

“As part of the scheme, Berezhnoy, Glebov, and others allegedly hacked into victim computer networks, copied and stole files and programs on the victims’ network, and encrypted the original versions of the stolen data with Phobos ransomware,” reads the U.S. DoJ announcement.

“The conspirators then allegedly extorted the victims for ransom payments in exchange for the decryption keys to regain access to the encrypted data by, among other things, leaving a ransom note on compromised victim computers and separately reaching out to victims to initiate ransom payment negotiations.”

“As alleged, the conspirators also threatened to expose victims’ stolen files to the public or to the victims’ clients, customers, or constituents if the ransoms were not paid.”

The two cybercriminals were arrested in separate locations in Phuket yesterday and now face a long list of charges that include:

  • Wire fraud conspiracy (1 count)
  • Wire fraud (1 count)
  • Conspiracy to commit computer fraud and abuse (1 count)
  • Intentional damage to protected computers (3 counts)
  • Extortion related to damage to a protected computer (3 counts)
  • Transmitting a threat to impair the confidentiality of stolen data (1 count)
  • Unauthorized access and obtaining information from a protected computer (1 count)

If convicted, they could receive a penalty of up to 20 years for wire fraud-related charges, 10 years for computer damage charges, and 5 years for the other counts.

The arrest and charging of the two Russian cybercriminals follows a similar action against Evgenii Ptitsyn, also a Russian national believed to have held an administrative role in the Phobos operation.

Europol infiltrated Phobos

In a separate announcement from Europol today, it was revealed that law enforcement authorities took down 27 servers associated with the 8Base ransomware group, ending its operations.

Yesterday’s news of the arrests in Thailand was directly linked to the appearance of seizure banners on 8Base’s extortion portals, but official confirmation of the action came earlier today.

Europol has also disclosed a key arrest of a Phobos affiliate in Italy in 2023, allowing its investigators to infiltrate the operation and gain intelligence that helped protect hundreds of targets.

“As a result of this operation, law enforcement was also able to warn more than 400 companies worldwide of ongoing or imminent ransomware attacks,” explains Europol.

Phobos has been active since December 2018, and while these law enforcement operations have somewhat disrupted it, the level of their impact is unclear at this time.

]]>
https://earlybirdsinvest.com/us-indicts-8base-ransomware-operators-for-phobos-encryption-attacks/feed/ 0 18824