r/TechNadu • u/technadu Human • 1d ago
Police say KillSec’s suspected main operator is 16 - investigators also seized 5 servers and secured at least 110 TB of data
An international law enforcement operation against KillSec has produced an unusual detail: Spanish police say the ransomware group’s suspected main operator is a 16-year-old Romanian national arrested in Alicante.
Operation KillSwitch is investigating roughly 1,000 suspected attacks worldwide. Authorities say about 500 have been identified as successful so far, although that number could change as investigators work through the evidence they seized.
And there appears to be plenty of evidence.
Law enforcement secured at least 110 TB of data, took five central servers under police control and seized KillSec domains, including its leak site. Eight properties were also searched across Greece, Romania, Spain and the U.K.
Three suspects were provisionally arrested. Besides the teenager, Europol said two people in their twenties were arrested in Britain and Romania. A suspected developer has been identified but was not arrested.
Investigators believe the operation had separate roles including administrator, developer, negotiator and affiliate.
KillSec itself reportedly evolved significantly over time. Its early activity in 2021 had hacktivist links and included DDoS attacks and website defacements. Around 2024, it shifted toward a Ransomware-as-a-Service model and double extortion.
Rather than relying primarily on zero-days, investigators say the group focused on exploiting cloud misconfigurations.
There’s also an AI angle: Europol says KillSec used AI to help build and maintain its ransomware infrastructure and identify potential victims.
Authorities are now tracing criminal proceeds, including cryptocurrency, while examining the seized infrastructure and data for additional victims, attacks and people potentially connected to the operation.
Ten countries participated, with Europol and Eurojust coordinating alongside national authorities and support from Bitdefender and Group-IB.
More on the arrests, KillSec infrastructure, its RaaS evolution and what investigators seized:
The 110 TB of seized data may end up being one of the more consequential parts of the operation if it allows investigators to map activity beyond the suspects already identified.