{"id":9886,"date":"2015-09-17T09:00:32","date_gmt":"2015-09-17T13:00:32","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=9886"},"modified":"2020-02-26T11:03:01","modified_gmt":"2020-02-26T16:03:01","slug":"criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/9886\/","title":{"rendered":"Criminals behind the CoinVault ransomware are busted by Kaspersky Lab and Dutch police"},"content":{"rendered":"<p>On Monday 14, September, <a href=\"https:\/\/securelist.com\/blog\/research\/72187\/coinvault-are-we-reaching-the-end-of-the-nightmare\/\" target=\"_blank\" rel=\"noopener noreferrer\">the Dutch police arrested two young men<\/a>, 18 and 22 years old, from Amersfoort, the Netherlands. The duo is suspected of attacking users PCs with the CoinVault ransomware. Since May 2014, the malware has targeted people in more than 20 countries, locking their devices and demanding ransom for bringing files back to the owners. The majority of victims had been registered in the Netherlands, Germany, USA, France and the UK.<\/p>\n<p><a href=\"https:\/\/securelist.com\/blog\/virus-watch\/67699\/a-nightmare-on-malware-street\/\" target=\"_blank\" rel=\"noopener noreferrer\">Since 2014 Kaspersky Lab has tracked the evolution of CoinVault<\/a> malware and collaborated with the National High Tech Crime Unit (NHTCU) of the Dutch police. The malware samples had flawless Dutch phrases throughout the binary code. As Dutch is a relatively difficult language to write without any mistakes, our specialists suspected the Dutch connection from the very beginning \u2014 And they were right!<\/p>\n<p>In November 2014 Kaspersky Lab and Dutch police launched <a href=\"https:\/\/noransom.kaspersky.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">noransom.kaspersky.com<\/a>, a tool that could be used to restore files encrypted by the CoinVault ransomware. It was the <a href=\"https:\/\/www.kaspersky.com\/blog\/coinvault-ransomware-removal-instruction\/8363\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">working alternative for victims<\/a> who either had to pay a ransom to the criminals or lose their files forever.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Learn how to remove CoinVault ransomware and restore your lost files \u2013 <a href=\"http:\/\/t.co\/OB02O372Yy\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/OB02O372Yy<\/a> <a href=\"http:\/\/t.co\/QjwzvIdKnz\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/QjwzvIdKnz<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/589108591346524162?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">April 17, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Later Kaspersky Lab was contacted by Panda Security, which had found information about additional malware samples that turned to be relative to CoinVault. A thorough analysis of the newly-found ransomware samples was given to the Dutch police. Our joint collaboration ended with real criminal apprehension.<\/p>\n<p>We are glad to see that the coordinated approach is being gradually built within the industry. Many security experts and AV companies make their own investigations, but only a few come forward with joint initiatives.<\/p>\n<p>The Dutch Police also recognized that, thanks to working together with market players they can catch more criminals. The <a href=\"https:\/\/www.kaspersky.com\/blog\/ask-expert-ransomware-epidemic\/9332\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">ransomware epidemic is a scourge of these days<\/a>, basically because only a few users consider this kind of malware a serious danger. But nobody can hide all the time and sooner or later many will be caught.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">How does Kaspersky Internet Security protect you from <a href=\"https:\/\/twitter.com\/hashtag\/ransomware?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#ransomware<\/a>? \u2013 <a href=\"http:\/\/t.co\/7drBP7PWxL\" target=\"_blank\" rel=\"noopener nofollow\">http:\/\/t.co\/7drBP7PWxL<\/a> <a href=\"http:\/\/t.co\/f5BDXJOC47\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/f5BDXJOC47<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/602008649846882305?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">May 23, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>It is much easier to <a href=\"https:\/\/www.kaspersky.com\/advert\/multi-device-security?redef=1&amp;THRU&amp;reseller=gl_KDpost_pro_ona_smm__onl_b2c_kasperskydaily_lnk____kismd___&amp;_ga=1.2461177.838268831.1450706896\" target=\"_blank\" rel=\"noopener nofollow\">protect a computer from malware<\/a>, then try to decrypt stolen files or pay a ransom. Keep your AV solution up to date at all times and make regular backups on a device without Internet connection, and you\u2019ll have a peaceful sleep. And please remember: if you pay a ransom you encourage criminals to keep going. Furthermore, it does not guarantee that the corrupted data will be given back to you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky Lab joined hands with the Dutch police to arrest the criminals behind the CoinVault dangerous ransomware.<\/p>\n","protected":false},"author":522,"featured_media":9887,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,2683],"tags":[335,1061,605,36,799,500,772,420],"class_list":{"0":"post-9886","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-arrests","10":"tag-coinvault","11":"tag-great","12":"tag-malware-2","13":"tag-malware-protection","14":"tag-malware-threats","15":"tag-police","16":"tag-ransomware"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/9886\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/5208\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/5691\/"},{"hreflang":"zh","url":"https:\/\/www.kaspersky.com.cn\/blog\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/3449\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/8910\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/9886\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/criminals-behind-the-coinvault-ransomware-are-busted-by-kaspersky-lab-and-dutch-police\/9886\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/arrests\/","name":"arrests"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/9886","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/522"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=9886"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/9886\/revisions"}],"predecessor-version":[{"id":33563,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/9886\/revisions\/33563"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/9887"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=9886"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=9886"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=9886"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}