{"id":6831,"date":"2025-09-11T10:03:26","date_gmt":"2025-09-11T10:03:26","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/11\/authorities-arrested-admins-of-lockergoga-megacortex-and-nefilim-ransomware-gangs\/"},"modified":"2025-09-11T10:03:26","modified_gmt":"2025-09-11T10:03:26","slug":"authorities-arrested-admins-of-lockergoga-megacortex-and-nefilim-ransomware-gangs","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/11\/authorities-arrested-admins-of-lockergoga-megacortex-and-nefilim-ransomware-gangs\/","title":{"rendered":"Authorities Arrested Admins Of \u201cLockerGoga,\u201d \u201cMegaCortex,\u201d And \u201cNefilim\u201d Ransomware Gangs"},"content":{"rendered":"<p>    Authorities Arrested Admins Of \u201cLockerGoga,\u201d \u201cMegaCortex,\u201d And \u201cNefilim\u201d Ransomware Gangs<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The U.S. District Court for the Eastern District of New York has unsealed a superseding indictment against a Ukrainian national, charging him with his alleged role as an administrator in the LockerGoga, MegaCortex, and Nefilim ransomware operations.<\/p>\n<p>The schemes reportedly extorted over 250 companies in the United States and hundreds more across the globe, causing millions of dollars in damages.<\/p>\n<p>The defendant, Volodymyr Viktorovich Tymoshchuk, also known by aliases such as \u201cdeadforz,\u201d \u201cBoba,\u201d \u201cmsfv,\u201d and \u201cfarnetwork,\u201d is facing multiple charges for his involvement in these widespread cyberattacks. <\/p>\n<p>\u201cVolodymyr Tymoshchuk is charged for his role in ransomware schemes that extorted more than 250 companies across the United States and hundreds more around the world,\u201d <a href=\"https:\/\/www.justice.gov\/opa\/pr\/lockergoga-megacortex-and-nefilim-ransomware-administrator-charged-ransomware-attacks\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">stated<\/a> Acting Assistant Attorney General Matthew R. Galeotti of the Justice Department\u2019s Criminal Division.<\/p>\n<p>He added that the attacks sometimes led to the complete disruption of business operations until the victims could recover or restore their encrypted data.<\/p>\n<p>According to the indictment, between December 2018 and October 2021, Tymoshchuk and his co-conspirators deployed the LockerGoga, MegaCortex, and Nefilim ransomware variants to encrypt computer networks in the U.S., France, Germany, the Netherlands, Norway, and Switzerland. <\/p>\n<p>The attackers customized the <a href=\"https:\/\/cybersecuritynews.com\/tag\/net-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a> for each victim, ensuring that the decryption key was unique. If a victim paid the ransom, they would receive a tool to unlock their files.<\/p>\n<p>\u201cTymoshchuk is a serial ransomware criminal who targeted blue-chip American companies, health care institutions, and large foreign industrial firms, and threatened to leak their sensitive data online if they refused to pay,\u201d said U.S. Attorney Joseph Nocella Jr. for the Eastern District of New York. <\/p>\n<p>From July 2019 to June 2020, the group allegedly compromised the networks of hundreds of companies with LockerGoga and MegaCortex. <\/p>\n<p>However, law enforcement successfully thwarted many of these attacks by notifying victims before the ransomware could be fully deployed.<\/p>\n<p>Following the initial wave of attacks, Tymoshchuk is alleged to have become an administrator for the Nefilim ransomware from July 2020 to October 2021. <\/p>\n<p>He and other administrators provided the ransomware to affiliates, including co-defendant Artem Stryzhak, in exchange for a 20% cut of the ransom proceeds. <\/p>\n<p>Stryzhak was previously extradited from Spain and faces charges in the same district. The charges against Tymoshchuk include conspiracy to commit computer fraud, intentional damage to a protected computer, and transmitting threats to disclose confidential information.<\/p>\n<p>The investigation, led by the FBI, is part of a broader international effort involving authorities in France, the Czech Republic, Germany, Lithuania, Luxembourg, the Netherlands, Norway, Switzerland, and Ukraine, with support from Europol and Eurojust. <\/p>\n<p>In a significant blow to the ransomware groups, decryption keys for LockerGoga and MegaCortex were released to the public in September 2022 through the \u201cNo More Ransomware Project,\u201d allowing victims to recover their data without paying a ransom.<\/p>\n<p>Concurrent with the indictment, the U.S. Department of State\u2019s Transnational Organized Crime Rewards Program is offering a reward of up to $11 million for information leading to the arrest, conviction, or location of Tymoshchuk or his conspirators.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/authorities-arrested-admins\/\">Authorities Arrested Admins Of \u201cLockerGoga,\u201d \u201cMegaCortex,\u201d And \u201cNefilim\u201d Ransomware Gangs<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/authorities-arrested-admins\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Authorities Arrested Admins Of \u201cLockerGoga,\u201d \u201cMegaCortex,\u201d And \u201cNefilim\u201d Ransomware Gangs The U.S. District Court for the Eastern District of New York has unsealed a superseding indictment against a Ukrainian national, charging him with his alleged role as an administrator in the LockerGoga, MegaCortex, and Nefilim ransomware operations. The schemes reportedly extorted over 250 companies in [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,231],"tags":[130],"class_list":["post-6831","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-ransomware","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6831"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6831"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6831\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}