<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Law-Enforcement on CuraSec</title><link>https://curasec.metacog.co.kr/tags/law-enforcement/</link><description>Recent content in Law-Enforcement on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/law-enforcement/index.xml" rel="self" type="application/rss+xml"/><item><title>Russian Extradited for 2016–17 Excel Malware Campaign Hitting 80K Freelancers</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-extradited-russian-hacker-faces-charges-over-excel-malware-c/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-extradited-russian-hacker-faces-charges-over-excel-malware-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Decade-old campaign with no current exploitation or IOCs; useful as historical context for malicious-attachment lure tradecraft but yields no actionable detection work today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Demonstrates ongoing DoJ extradition efforts against cybercrime actors; no immediate vendor exposure or board-level risk action required given the 2016–17 vintage of the campaign.&lt;/li>
&lt;/ul></description></item><item><title>Sality P2P Botnet Dismantled by Multi-Nation Law Enforcement Op</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-authorities-turn-sality-s-p2p-network-against-itself-cutting/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-authorities-turn-sality-s-p2p-network-against-itself-cutting/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Sality is a long-running Windows file-infector botnet; the takedown disrupts payload delivery but poses no new patching requirement. Worth understanding the P2P sinkholing technique for resilience lessons in your own defenses.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Review whether any endpoints in your estate show Sality indicators; the takedown disruption of C2 may cause anomalous beacon behavior from previously silent infections — tune EDR/SIEM to surface residual Sality activity in the next few weeks.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A successful multi-nation, public-private botnet disruption with industry partners demonstrates the operational model; useful context for board-level discussions on law enforcement collaboration and infrastructure resilience.&lt;/li>
&lt;/ul></description></item><item><title>Sality P2P botnet infrastructure seized in international takedown</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-sality-botnet-infrastructure-dismantled-in-joint-global-take/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-sality-botnet-infrastructure-dismantled-in-joint-global-take/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Sality has been a persistent Windows endpoint threat for years; the C2 sinkholing creates a window to identify residual infections in your estate, but no IOCs or TTPs are provided in this summary to act on directly.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A notable coordinated takedown of a long-running global botnet, useful context for board-level situational awareness on law enforcement effectiveness, but no organizational action is required.&lt;/li>
&lt;/ul></description></item><item><title>INTERPOL Operation Jackal IV Arrests 58 in Global Cyber Fraud Sweep</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-interpol-operation-jackal-iv-arrests-58-identifies-263-in-gl/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-interpol-operation-jackal-iv-arrests-58-identifies-263-in-gl/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Operation Jackal IV provides updated context on West African cybercrime network scale and reach; no IOCs or TTPs published, so no immediate detection work, but useful for understanding threat actor landscape if your sector is targeted by BEC or fraud campaigns linked to these groups.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A 22-country enforcement action against Black Axe and similar networks signals growing international pressure on cyber fraud groups; useful background for board-level threat landscape briefings, but no immediate organizational action required.&lt;/li>
&lt;/ul></description></item><item><title>Global police op arrests 58 suspects tied to African cybercrime networks</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-police-arrests-dozens-of-suspects-in-global-cybercrime-crack/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-police-arrests-dozens-of-suspects-in-global-cybercrime-crack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Awareness of disrupted cybercrime infrastructure can inform threat landscape understanding, but no IOCs, TTPs, or detection opportunities are surfaced in this reporting.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Demonstrates continued international enforcement pressure on cybercrime networks; useful context for board-level threat landscape briefings but requires no immediate action.&lt;/li>
&lt;/ul></description></item><item><title>Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-ransom-cartel-creator-gets-16-years-in-prison-for-operating/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-ransom-cartel-creator-gets-16-years-in-prison-for-operating/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Background on the Ransom Cartel RaaS model (2021–2023) is useful for understanding affiliate-driven ransomware tradecraft, but the operation is dismantled and no new IOCs or detection angles are provided.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A successful DOJ prosecution of a major RaaS operator is useful context for board or customer conversations about ransomware deterrence, but it changes no current risk posture or vendor exposure.&lt;/li>
&lt;/ul></description></item><item><title>Ransom Cartel creator sentenced to 16 years for ransomware attacks</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-ransom-cartel-ransomware-creator-sentenced-to-16-years-in-pr/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-ransom-cartel-ransomware-creator-sentenced-to-16-years-in-pr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Notable law enforcement outcome against a prolific ransomware operator; useful context for understanding Ransom Cartel&amp;rsquo;s operational history but yields no detection or hunting actions.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A 16-year sentence for a ransomware-as-a-service creator is a benchmark-level enforcement outcome worth referencing in board-level discussions on deterrence and the evolving legal risk landscape for threat actors.&lt;/li>
&lt;/ul></description></item><item><title>ExfilSquad leaks data on 100,000+ UK police officers from PNLD breach</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-exfilsquad-hackers-leak-info-of-over-100-000-uk-police-offic/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-exfilsquad-hackers-leak-info-of-over-100-000-uk-police-offic/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A large-scale personnel-data breach at a UK criminal justice database is a useful benchmark for board discussions on insider/third-party data exposure risk, but requires no direct action for US/global enterprise leaders without PNLD dependencies.&lt;/li>
&lt;/ul></description></item><item><title>Europol flags 4,340 URLs in 'The Com' violent extremist crackdown</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-europol-flags-4-340-urls-for-removal-in-the-com-crackdown/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-europol-flags-4-340-urls-for-removal-in-the-com-crackdown/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The Com is a loosely organized nihilistic violent extremist network; awareness of this enforcement action provides context for potential future threat actor tracking, but no IOCs or detection artifacts are surfaced here.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A large-scale Europol content removal operation against a violent extremist network is useful situational awareness for threat landscape briefings, but requires no immediate organizational action.&lt;/li>
&lt;/ul></description></item><item><title>Police dismantle Kratos phishing platform, arrest developer</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-platform-arrest-developer/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-platform-arrest-developer/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The Kratos PhaaS takedown removes active infrastructure but no IOCs or TTPs are published in this item, so there is no immediate detection or hunt to run; useful background on the phishing-as-a-service ecosystem.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A major PhaaS platform serving global customers has been dismantled — useful context for threat landscape briefings, but no immediate vendor exposure or regulatory action is required.&lt;/li>
&lt;/ul></description></item><item><title>Armenia Detains Russian Tourist in REvil Extradition Mix-Up</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-armenia-detains-russian-tourist-on-u-s-warrant-for-revil-hac/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-armenia-detains-russian-tourist-on-u-s-warrant-for-revil-hac/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Background context on REvil prosecution efforts; no IOCs, TTPs, or detection actions arise from this legal/identity dispute.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates ongoing U.S. pursuit of ransomware actors via allied extradition — useful context for board-level ransomware risk narratives, but no immediate action required.&lt;/li>
&lt;/ul></description></item><item><title>Spanish Police dismantle €140M BEC and investment fraud ring</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-spanish-police-take-down-140-million-cyber-fraud-ring-arrest/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-spanish-police-take-down-140-million-cyber-fraud-ring-arrest/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> BEC at this scale is a useful reminder to review email authentication controls and employee awareness, but no IOCs or TTPs are published from this takedown.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A €140M fraud operation highlights BEC as a material financial risk; useful context for board-level discussions on business email compromise exposure and vendor payment controls.&lt;/li>
&lt;/ul></description></item><item><title>US charges alleged operators of Russian bulletproof hosting service</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-us-charges-alleged-operators-of-russian-bulletproof-hosting/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-us-charges-alleged-operators-of-russian-bulletproof-hosting/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Law enforcement action against ransomware-enabling infrastructure is worth tracking for actor context, but no IOCs or TTPs are published here that support immediate detection work.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The indictment signals continued US pressure on ransomware infrastructure and is useful context for board-level threat landscape briefings, but requires no immediate organizational action.&lt;/li>
&lt;/ul></description></item></channel></rss>