Categories: Canada

Civilians behind international police probe into Russian cybercriminals – National


An RCMP sergeant says civilian cybercrime investigators were instrumental in helping the Mounties and international partners deal a blow to cybercriminals trying to infect WordPress websites.

Sgt. Warren Krahenbil, leader of the RCMP’s Federal Cybercrime Investigative Team in Vancouver, outlined Operation Endgame in an interview with Global News on Sunday.

The operation targeted SocGholish malware – linked to the Russian cybercriminal group Evil Corp. Investigators say the group exploited thousands of WordPress sites to gain unauthorized access to computer systems.

“The malware did infect a large number of WordPress websites,” Krahenbil said, “it’s tailored to certain sites, though.”

The Mounties teamed up with counterparts in the Netherlands, the United States and Germany on the joint action, according to a media statement.

Story continues below advertisement

A notice from the Dutch police said agencies took down 106 servers and domains worldwide, remediated almost 15,000 websites, cleaned infected WordPress sites and notified the group’s victims.

Get daily National news

Get daily Canada news delivered to your inbox so you’ll never miss the day’s top stories.

“One of our civilian experts came up with a way to decode pieces of the SocGholish code and that sort of gave us a ‘springboard’ to work forward and share with the international community,” Krahenbil said.

Owners of WordPress websites are being urged to change their credentials, enable multi-factor authentication, delete any unknown WordPress accounts and keep their site up to date, he said.

People are warned to never trust pop-ups that appear in browsers or flashy update notices that urge immediate action to prevent a potential SocGholish malware infection.


Anyone who does not use WordPress should still take precautions “like you would every day on the internet,” Krahenbil said. This includes using antivirus software, keeping track of passwords, and using a password manager if possible.

“If you’re not using WordPress, you should be OK,” he said. “But also be aware of what you click on online. Make sure that every link that you follow is the link that you’re going to.”

It’s believed SocGholish was using its malware to both obtain money and intelligence.

“When you’re infected with SocGholish, they have access and then they use that access to download additional malware to control the computer, to search the computer and extract data,” Krahenbil added.

Story continues below advertisement

with files from The Canadian Press

&copy 2026 Global News, a division of Corus Entertainment Inc.



Source link

admin2

Share
Published by
admin2

Recent Posts

Kurv Launches SpaceX Enhanced Income ETF

On June 17, Kurv Investment Management launched the Kurv SpaceX Enhanced Income ETF (XSHP), on…

3 hours ago

US and Iran meet for ‘tense’ but ‘constructive’ ceasefire talks | US-Israel war on Iran

NewsFeedNegotiators from the US and Iran wrapped a day of talks in Switzerland as they…

3 hours ago

Bitcoin Prediction From February Comes Back Into Focus As BT

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure An older…

4 hours ago

Feds’ AI bill good ‘first step’ but safety advocates say more work needed – National

The federal government’s proposed online safety legislation is a good start on regulating artificial intelligence…

5 hours ago

Man wanted in Ottawa after allegedly removing woman’s hijab: police – Ottawa

Ottawa police say they’re searching for a man after a woman had her hijab removed…

8 hours ago

Midstream Energy ETFs Prove Resilient Amid Crude Oil Drop

The midstream energy segment is standing out for its resilience as oil prices face downward…

8 hours ago