Vastaamo Compromise Suspect Caught In France

An update to my blog yesterday:

Most notable was the method in which he was caught:

But as documented by KrebsOnSecurity in November 2022, security experts soon discovered Ransom Man had mistakenly included an entire copy of their home folder, where investigators found many clues pointing to Kivimäki’s involvement. From that story:

“Among those who grabbed a copy of the database was Antti Kurittu, a team lead at Nixu Corporation and a former criminal investigator. In 2013, Kurittu worked on an investigation involving Kivimäki’s use of the Zbot botnet, among other activities Kivimäki engaged in as a member of the hacker group Hack the Planet (HTP).”

“It was a huge opsec [operational security] fail, because they had a lot of stuff in there — including the user’s private SSH folder, and a lot of known hosts that we could take a very good look at,” Kurittu told KrebsOnSecurity, declining to discuss specifics of the evidence investigators seized. “There were also other projects and databases.”

https://krebsonsecurity.com/2023/02/finlands-most-wanted-hacker-nabbed-in-france/

Check out the full article at: https://krebsonsecurity.com/2023/02/finlands-most-wanted-hacker-nabbed-in-france/

Leave a Reply

Your email address will not be published. Required fields are marked *