Connect with us

Published

on

US DOJ seizes M in crypto from accused Qakbot malware developer

The US Department of Justice (DOJ) has filed a civil forfeiture complaint to seize more than $24 million in cryptocurrency from Rustam Rafailevich Gallyamov, a Russian national accused of developing the Qakbot malware.

According to a May 22 announcement, the DOJ unsealed charges against the 48-year-old Moscovite with a federal indictment. Gallyamov is allegedly the malware developer behind the Qakbot botnet.

“Today’s announcement of the Justice Department’s latest actions to counter the Qakbot malware scheme sends a clear message to the cybercrime community,” said Matthew Galeotti, head of the DOJ’s criminal division.

US DOJ seizes $24M in crypto from accused Qakbot malware developer
Screenshot of the indictment. Source: US Department of Justice

Galeotti highlighted that the DOJ is “determined to hold cybercriminals accountable.” He added that the department will “use every legal tool” to “identify you, charge you, forfeit your ill-gotten gains, and disrupt your criminal activity.”

Related: Microsoft takes legal action against infostealer Lumma

Over $24 million forfeited

US Attorney Bill Essayli for the Central District of California explained that “the criminal charges and forfeiture case announced today are part of an ongoing effort” to “identify, disrupt, and hold accountable cybercriminals.” He added:

“The forfeiture action against more than $24 million in virtual assets also demonstrates the Justice Department’s commitment to seizing ill-gotten assets from criminals in order to ultimately compensate victims.”

Assistant Director in Charge Akil Davis of the FBI’s Los Angeles Field Office said that Qakbot was crippled by the agency and its partners in 2023. Still, Gallyamov allegedly continued deploying alternative methods to offer his malware to potential partners.

Related: Chinese printer maker spread Bitcoin stealing malware — Report

Qakbot used in global ransomware attacks

Gallyamov allegedly operated the Qakbot malware as far back as 2008. In 2019, he allegedly used it to infect thousands of victim computers to establish a so-called botnet.

Access to computers that were part of the botnet was sold to others who infected them with ransomware, including Prolock, Dopplepaymer, Egregor, REvil, Conti, Name Locker, Black Bast and Cactus. In 2023, a US-led international operation disrupted the Qakbot botnet and malware.

At the time, over 170 Bitcoin (BTC) and over $4 million in USDt (USDT) and USDC (USDC) stablecoins were seized from Gallyamov. According to the indictment, he and his collaborators continued the activity after it was disrupted, adopting new techniques, including directly deploying Black Basta and Cactus ransomware.

Magazine: Report on Crypto Exchange Hacks

Continue Reading

Politics

Upbit operator Dunamu posts $165M in profit in Q3, up over 300% YoY

Published

on

By

Upbit operator Dunamu posts 5M in profit in Q3, up over 300% YoY

Upbit operator Dunamu reported a surge in profitability for the third quarter of the year, posting 239 billion won ($165 million) in net income.

The figure marks an increase of more than 300% compared to the same period last year, which stood at $40 million, local news outlet Chosun Biz reported, citing regulatory filings with the Financial Supervisory Service.

The filing reportedly showed strong momentum across all key metrics. Consolidated revenue climbed to $266 million, up 35% from the previous quarter, while operating profit rose 54% to $162 million. Net income also jumped 145% quarter-over-quarter from $67 million.

The company attributed its improved performance to rising trading activity as global digital asset markets rebounded through 2024 and 2025.

Related: South Korea’s bank-first stablecoin approach lacks logic, says Kaia chair

Dunamu credits US crypto bills for boost

Dunamu said investor confidence received a boost following regulatory developments in the United States, including the passage of the Genius Act, the Clarity Act and the Anti-CBDC Bill. These measures, the company said, contributed to renewed institutional participation and steadier market conditions.

Dunamu has faced heightened reporting requirements since 2022, when it was added to the list of corporations subject to external audit due to having more than 500 shareholders.

Notably, several major crypto firms experienced a revenue increase last quarter. Bitcoin mining company TeraWulf and Singapore-based cloud Bitcoin miner BitFuFu doubled their third-quarter revenue from the previous year.

Related: South Korea ramps up crypto seizures, will target cold wallets

Naver Financial to acquire Dunamu

As Cointelegraph reported, Naver Financial, the fintech arm of South Korea’s largest internet company, is preparing to acquire Dunamu. Naver reportedly plans to bring Dunamu in as a subsidiary through a share swap, with board approvals expected soon.