[ad_1]
Blockchain and cryptocurrency infrastructure provider Binance shared details of its role in the June 16, 2021 raid on elements of the Cl0p (aka Clop) ransomware team in Ukraine, revealing how the expansion of its internal cyber capabilities has generated strong evidence that cybercriminals are taking advantage of cryptocurrency exchanges in their work.
While the raid on Cl0p is now widely recognized by observers as having been a withdrawal of more peripheral elements associated with the gang, with the big guns still suspected of being on the run, as evidenced by the recent appearance of new casualties on their dark web leak site. , the joint raid in early June again resulted in the seizure of assets, including cash, computer equipment and luxury cars, as well as several arrests.
The group is believed to have laundered substantial sums of extorted cryptocurrency and allegedly caused more than $ 500 million in damage during its long wave of crimes.
Binance said that over the past year, it has expanded its internal anti-money laundering detection and analysis capabilities and, based on its subsequent research and analysis, as well as its Current understanding of cybercriminals’ withdrawal tactics, he came to the conclusion that the biggest security issue in the cryptocurrency industry is money earned in laundered cyberattacks through nested services and exchanger accounts parasites living inside macro virtual asset service providers (VASPs), including its own exchange Binance.com. This network of money launderers makes deposits and withdrawals between them in order to wash the money.
These criminals like to take advantage of the liquidity of reputable exchanges, various offerings of digital assets and well-developed APIs, the organization said.
In the majority of cases associated with illicit blockchain flows entering the exchanges, the exchange does not host the criminal group itself, but rather is used as an intermediary to launder stolen profits.
With that understood, Binance is now implementing a two-pronged approach to cracking down on it, implementing a new detection mechanism to identify and eliminate suspicious accounts, and providing information to law enforcement to build cases. and disrupt criminal networks in the physical world.
He applied this approach to the investigation that led to Cl0p led by a group dubbed Fancycat which was coordinated through an international effort including law enforcement from South Korea, Spain, Switzerland, Ukraine. and the United States.
Fancycat was involved in multiple cybercrime activities, including distributing cyber attacks, operating high-risk exchangers, and laundering money from dark web operations and high-profile attacks associated with Cl0p and Petya ransomware.
Our AML detection and analysis program detected suspicious activity on Binance.com and extended the suspicious cluster, Binance said.
Once we mapped the entire suspect network, we worked with private sector chain analysis companies TRM Labs and Crystal (BitFury) to analyze on-chain activity and better understand this group and its attribution.
Based on our analysis, we found that this specific group was not only associated with Cl0p attack money laundering, but also with Petya and other illegally sourced funds. This led to the identification and eventual arrest of Fancycat.
The organization added: At Binance, we believe that tight controls on exchanges, smart legislation, and ongoing education will go a long way in eliminating bad players. Projects such as our Bulletproof Exchanger and our ongoing partnerships with law enforcement, as well as security analytics and blockchain companies, will be a driving force to improve cybersecurity metrics across the world. crypto industry.
[ad_2]
picture credit