On June 11, 2025, INTERPOL made an announcement regarding the successful dismantling of over 20,000 malicious IP addresses and domains associated with 69 information-stealing malware variants. This operation, dubbed Operation Secure, was carried out between January and April 2025, with the collaboration of law enforcement agencies from 26 countries. The efforts involved identifying servers, mapping physical networks, and executing targeted takedowns, resulting in the removal of 79% of suspicious IP addresses.
According to INTERPOL, participating countries seized 41 servers and over 100 GB of data, leading to the arrest of 32 suspects involved in illegal cyber activities. Vietnamese authorities arrested 18 suspects and confiscated devices and documents worth $11,500. Additionally, house raids in Sri Lanka and Nauru led to the arrest of 12 individuals and two individuals, respectively. The Hong Kong Police identified 117 command-and-control servers hosted across 89 internet service providers, used for launching malicious campaigns such as phishing and online fraud.
Countries involved in Operation Secure include a wide range of nations, such as Brunei, Cambodia, India, Japan, Malaysia, Philippines, South Korea, and Vietnam, among others. This operation followed the recent seizure of 2,300 domains associated with the Lumma Stealer malware. Information stealers, sold on the cybercrime underground, enable threat actors to gain unauthorized access to target networks by extracting sensitive data like browser credentials, passwords, and credit card details.
Group-IB, a Singapore-headquartered company that participated in the operation, provided crucial intelligence related to compromised user accounts by stealer malware like Lumma and RisePro. CEO Dmitry Volkov highlighted the significance of preventing cybercriminals from using stolen data for financial fraud and ransomware attacks. The stolen information is often monetized on forums, paving the way for follow-on attacks like data breaches and business email compromise. This successful operation underscores the ongoing battle against cyber threats and the importance of international cooperation in combating cybercrime.
Source link
