International Operation Dismantles KillSec Ransomware Group
Share
International law enforcement agencies, led by German police and Europol, have successfully disrupted the KillSec ransomware group, responsible for hundreds of cyberattacks since 2024. The coordinated operation, dubbed Operation KillSwitch, resulted in multiple arrests, including a suspected 16-year-old ringleader, and the seizure of key infrastructure.
Authorities confirmed that the operation prevented the exposure of at least 110 terabytes of stolen data and seized five servers used to manage the group’s activities and store victim data. Several KillSec domains have also been taken down and now redirect visitors to a police seizure notice.
Key Members Arrested and Indicted
The multinational investigation involved law enforcers from Spain, Greece, Romania, and the UK, conducting eight house searches. Three provisional arrests were made, including a 16-year-old Romanian national apprehended in Alicante, Spain, who is believed to be the administrator and main operator of KillSec.
Investigators also identified a suspected developer, who turned 18 in August 2026, a negotiator, and an affiliate involved in the group’s operations. The collaboration across jurisdictions was crucial in targeting the core team behind the sophisticated ransomware-as-a-service (RaaS) outfit.
Further strengthening the operation, US authorities announced the indictment of Fouad Eltibrizi, also known as “Archduke,” a Dutch national residing in the UK. Eltibrizi was arrested on September 30 by British police and faces hacking and extortion-related charges that carry a maximum sentence of 10 years in prison.
KillSec’s Operations and Impact
KillSec had been active since 2024, successfully executing at least 500 cyberattacks and being linked to twice that number of attempted intrusions, according to Europol. The group primarily targeted organisations by exploiting software vulnerabilities and poorly secured cloud storage access points.
Cybersecurity firm Group-IB, which assisted in the operation, identified 274 publicly claimed victims, with a significant concentration in the US (35%) and India (17%). KillSec was observed using Windows and VMware ESXi virtualization lockers, though it did not always encrypt data. In some instances, the group focused solely on data theft and extortion, acting as both a ransomware operator and a data broker, advertising stolen information for prices ranging from $5,000 to $500,000.
Dmitry Volkov, CEO of Group-IB, highlighted the severe impact of such groups, stating, “KillSec’s affiliates went after the organizations people depend on most: hospitals, government bodies, and financial institutions.” He emphasised that while servers can be replaced, identifying and bringing the people who build and approve attacks to justice is what turns a takedown into an end, rather than just a pause.
The successful disruption of KillSec marks a significant victory for international law enforcement in the ongoing fight against sophisticated ransomware operations.




Leave a Reply