Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Iranian-Nexus Targets Oman Ministries: Webshells & Data
May 6, 2026
Remus Infostealer Uses Lumma-Style Browser Key Theft and
May 6, 2026
Zero-Auth Flaw Exposes DoD Contractor Cross- Cross-Tenant Data
May 6, 2026
Home/CyberSecurity News/Ukraine Police Expose Russian Hacker Group Specializing in Ransom
CyberSecurity News

Ukraine Police Expose Russian Hacker Group Specializing in Ransom

Law enforcement agencies in Ukraine and Germany have disrupted a Russian-affiliated hacker group. The group conducted high-impact ransomware attacks against organizations globally, causing estimated...

David kimber
David kimber
January 19, 2026 2 Min Read
1 0

Law enforcement agencies in Ukraine and Germany have disrupted a Russian-affiliated hacker group. The group conducted high-impact ransomware attacks against organizations globally, causing estimated losses in the hundreds of millions of euros.

According to Ukraine’s Cyber Police and the Main Investigation Department of the National Police, working under the guidance of the Cyber Department of the Prosecutor General’s Office.

In cooperation with Germany’s Federal Criminal Police Office (BKA), two members of the group operating from Ukraine have been identified and searched.

Technical Roles in Ransomware Operations

Investigators say the suspects played key technical roles within the ransomware operation. They acted as “hash crackers” specialists who used dedicated tools to extract and crack password hashes from compromised systems.

After stealing or cracking employee credentials, the attackers allegedly used these accounts to move laterally inside corporate networks, escalate privileges, and gain control over critical infrastructure.

(source: Cyber ​​Police of Ukraine)

Once inside, the group is believed to have deployed ransomware to encrypt sensitive data and systems and to exfiltrate confidential information.

Then, the extortionists demanded payment for decryption keys and to prevent data leaks.

Searches were carried out at the suspects’ residences in the Ivano-Frankivsk and Lviv regions of Ukraine.

Police seized digital media, devices, and cryptocurrency assets believed to be linked to the illegal activity.

Law enforcement describe the cybercrime group
Law enforcement describe the cybercrime group (source: Cyber ​​Police of Ukraine)

As part of a broader joint investigation with Europol, authorities have also identified the alleged organizer, a Russian citizen suspected of creating and leading the group.

Foreign partners report that he may also have ties to the notorious Conti ransomware operation.

On the initiative of Germany’s BKA and the Central Office for Combating Cybercrime (ZIT) in Frankfurt am Main, he has been placed on an international wanted list via Interpol.

Law enforcement agencies describe the gang as one of the most dangerous cybercriminal groups in recent years, targeting companies, institutions, and government bodies in economically developed Western countries between 2022 and 2025.

The case highlights deep international cooperation among Ukraine, Germany, Switzerland, the Netherlands, and the United Kingdom to track, attribute, and disrupt cross-border ransomware operations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerransomware

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Malicious Chrome Extensions Attack Enterprise HR & ERP

Next Post

Livewire Filemanager RCE Vulnerability Affects Web Applications

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Azure AD Conditional Access Bypass: Phantom Device PR
May 6, 2026
Critical Palo Alto Firewall Vulnerability Exploited for Root Access
May 6, 2026
Optimize SOC Costs & Boost Confidence with Better Threat Intelligence
May 5, 2026
Top Authors
Sarah simpson
Sarah simpson
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us