
Authorities in Spain have arrested a 16 year-old boy accused of involvement in the KillSec ransomware gang, which is thought to have conducted over 1,000 cyber attacks over the past couple of years.
The unnamed minor, who is a Romanian national, was taken into custody in a joint operation by Spain’s national Guardia Civil police force and the Catalan authorities, following searches at two addresses in the southern city of Alicante, one a private home, the other a hotel.
The Guardia Civil said its officers seized computer equipment, mobile phones, cryptocurrency wallets, and various tools designed to mask the gang’s activities.
The arrest comes amid a wider takedown operation – coordinated by Hamburg state authorities in Germany – targeting the KillSec ransomware gang. Dubbed Operation KillSwitch, the sting saw searches conducted in Greece, Romania and the UK, and two additional arrests made. Law enforcement also seized KillSec’s leak site and secured approximately 100TB of data stolen from the gang’s victims.
Andy Grote, senator for the interior of the City of Hamburg, said: “This international strike against the KillSec group marks the second international operation in just a few months in which Hamburg’s State Criminal Police Office has played a key role.
“The operation was intensively prepared from Hamburg and coordinated in cooperation with international partners. This demonstrates the strength and effectiveness of Hamburg’s security agencies in combating the most serious forms of cyber crime.
“It also sends a signal to anyone who commits grave crimes while believing themselves safe within the apparent anonymity of the internet. I thank everyone involved for their tremendous efforts,” said Grote.
Dutch national
Computer Weekly understands that one of the arrests, made in the UK, was of a Dutch national who was named and indicted today by the US Department of Justice as Foaud Eltibrizi, also known as ‘Archduke’. He now faces extradition to the US.
“The defendant and his co-conspirators carried out targeted intrusions against multiple companies and organisations, stealing highly sensitive information and attempting to extort their victims for substantial sums of money,” said Héctor Ramírez‑Carbó, acting US attorney for the district of Puerto Rico, where the charges were unsealed.
“Ransomware remains a serious and evolving threat to all sectors of our economy, from critical infrastructure to small businesses. The Justice Department and the US Attorney’s Office for the District of Puerto Rico will continue to work closely with our international partners to identify, disrupt, and prosecute anyone – anywhere – who seeks to harm US and Puerto Rico businesses and consumers through these attacks,” said Ramírez‑Carbó.
The identities of the other alleged cyber criminals has not been revealed and additional investigations into other potential gang members continue.
Healthcare and financial services were key targets
According to Singapore-based cyber company Group-IB, which provided behind-the-scenes support during Operation KillSwitch, the KillSec gang – also variously known as Kill Security and k1llsec, emerged in 2024 and rapidly established itself as a significant player in the ransomware-as-a-service (RaaS) ecosystem, widely recruiting affiliate hackers.
Group-IB said it had identified at least 274 publicly-disclosed victims, with the US accounting for around 35%, Europe accounting for approximately 14%, and the UK for roughly 3%.
Initially favouring Windows environments, KillSec began targeted VMware ESXi hosts in November 2024 as part of a major expansion that also saw it move to increase its share of the ransoms its affiliates garnered.
In general, its attacks followed the ‘path-of-least-resistance’ with victims targeted via phishing, brute-force attacks on exposed Remote Desktop Protocol (RDP) services, known vulnerabilities in internet-facing applications, and misconfigured cloud storage vaults. There is also evidence that its operatives were more recently using artificial intelligence (AI) to build and run its infrastructure, and research potential victims.
In its targeting, KillSec favoured financial services and healthcare organisations – predominantly technology companies whose products were used by clinics and hospitals – but its list of victims also includes large enterprises and government bodies. Throughout its lifetime, it acted as both a data broker and a ransomware operator.
“KillSec's affiliates went after the organisations people depend on most: hospitals, government bodies, and financial institutions,” said Group-IB CEO Dmitry Volkov.
“Closing the gaps these groups exploit is essential, but it does not end an operation like this. Servers can be replaced in weeks; the people who build the platform and approve every attack cannot. Identifying them and supporting law enforcement in bringing them to justice is what turns a takedown from a pause into an end. We are proud to have contributed to Operation KillSwitch, and will continue to support Europol and our law enforcement partners in the fight against cyber crime.”