US erhebt Anklage gegen mutmaßlichen Redline-Infostealer-Entwickler, Admin

Teilen:

The identity of a suspected developer and administrator of the Redline malware-as-a-service operation has been revealed: Russian national Maxim Rudometov.

Infrastructure takedown

As promised on Monday when they announced the disruption of the Redline and Meta infostealer operations, law enforcement Operation Magnus has unveiled on Tuesday how the takedown played out.

“Investigations into Redline and Meta started after victims came forward and a security company notified authorities about possible servers in the Netherlands linked to the software. Authorities discovered that over 1,200 servers in dozens of countries were running the malware,” shared Eurojust, the European Union Agency for Criminal Justice Cooperation.

Eurojust coordinated the information exchange between and actions taken by authorities from the Netherlands, the United States, Belgium, Portugal, United Kingdom and Australia, which resulted in three servers taken down in the Netherlands, two seized domains, the disruption of several Redline and Meta communication channels (Telegram), and two people – suspected customers of Rudometov’s – being taken into custody in Belgium.

“The authorities also retrieved a database of clients from Redline and Meta. Investigations will now continue into the criminals using the stolen data,” Eurojust added.

The security company mentioned in the latest announcements is ESET, which also made available a scanner that Windows users can leverage to check whether they’ve been infected with the Redline or Meta stealers and to remove the malware (if present).

It is estimated that the Redline and Meta infostealers stole information from millions of victims around the world.

Pinpointing the person behind the operation

Law enforcement managed to connect various online monikers and email addresses used by Rudometov over the years on hacking forums and link some to a VK (Russian social network) account in that name.

“A judicially-authorized search of [the Apple account registered with one of those email addresses] revealed an associated iCloud account and numerous files that were identified by antivirus engines as malware, including at least one that was analyzed by the Department of Defense Cybercrime Center (‘DC3’) and determined to be Redline,” the unsealed criminal complaint against Rudometov says.

“Notably, among the malicious files saved to Rudometov’s Apple iCloud Drive was a file entitled ‘MysteryPanel.rar’ which correlates to the [Redline infostealer]. In addition to the registration information indicating Rudometov was the owner of the Apple account, the account contained photos that included Rudometov’s official identification documents and apparent personal photos.”

He has also been tied with a number of cryptocurrency accounts that were used to receive and launder payments, and the malware was hosted on servers controlled and accessed by him.

Rudometov has been charged by the US Department of Justice with access device fraud, conspiracy to commit computer intrusion, and money laundering.

The DOJ press release does not mention whether Rudometov is in police custody, which means he’s most likely not.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:08 pm, Jan. 31, 2025
Wetter-Symbol 7°C
L: 6° | H: 7°
overcast clouds
Luftfeuchtigkeit: 92 %
Druck: 1028 mb
Wind: 5 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 7:40 am
Sonnenuntergang: 4:47 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 9:00 pm
Wetter-Symbol
6° | 7°°C 0 mm 0% 8 mph 90 % 1030 mb 0 mm/h
So. Feb. 02 9:00 pm
Wetter-Symbol
2° | 8°°C 0 mm 0% 6 mph 86 % 1026 mb 0 mm/h
Mo. Feb. 03 9:00 pm
Wetter-Symbol
2° | 9°°C 0 mm 0% 5 mph 92 % 1027 mb 0 mm/h
Di. Feb. 04 9:00 pm
Wetter-Symbol
3° | 9°°C 0 mm 0% 9 mph 93 % 1028 mb 0 mm/h
Mi. Feb. 05 9:00 pm
Wetter-Symbol
4° | 8°°C 0.51 mm 51% 7 mph 86 % 1045 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 5 mph 90 % 1028 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
5° | 6°°C 0 mm 0% 6 mph 84 % 1029 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 4 mph 80 % 1029 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
5° | 5°°C 0 mm 0% 3 mph 79 % 1030 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 8 mph 71 % 1029 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 6:00 pm
Wetter-Symbol
6° | 6°°C 0 mm 0% 6 mph 73 % 1027 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
4° | 4°°C 0 mm 0% 6 mph 82 % 1026 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€97,848.52
-3.28%
Ethereum(ETH)
€3,190.45
2.27%
XRP(XRP)
€2.90
-3.48%
Fesseln(USDT)
€0.96
-0.06%
Solana(SOL)
€220.87
-4.03%
USDC(USDC)
€0.96
0.00%
Dogecoin(DOGE)
€0.313779
-1.82%
Shiba Inu(SHIB)
€0.000018
0.23%
Pepe(PEPE)
€0.000013
8.08%
Nach oben scrollen