Ukrainian police arrest hacker who used hosting firm’s servers to mine cryptocurrency

Avatar

Ukrainian police, with assistance from Europol, have arrested a 35-year-old man accused of hacking into thousands of user accounts at an international hosting company and using its infrastructure to illegally mine cryptocurrency, authorities said Wednesday.

The suspect, a native of the central Ukrainian city of Poltava, had been conducting cyberattacks since at least 2018, police said. He allegedly gathered information from open sources to identify vulnerabilities in the systems of various international companies.

According to investigators, the hacker gained unauthorized access to more than 5,000 user accounts belonging to an unnamed global hosting provider that rents out servers to businesses operating websites and online platforms. Once inside, he allegedly deployed virtual machines on the company’s infrastructure to mine cryptocurrency without permission.

Ukrainian cyber police said the unauthorized mining operation caused an estimated $4.5 million in losses to the company.

During raids at several locations, officers seized computers, mobile phones, banking cards and other equipment. Forensic analysis revealed that the suspect maintained multiple accounts on hacker forums and used various malicious tools, such as software scripts for launching and managing crypto-mining operations and tools for data collection and remote control of compromised systems.

The man frequently changed his residence to avoid detection, police said. The investigation is ongoing.

CybercrimeGovernmentNewsNews Briefs
Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands

Next Post

Cyber Security Expo

Related Posts

Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access

Hewlett-Packard Enterprise (HPE) has released security updates to address a critical security flaw affecting Instant On Access Points that could allow an attacker to bypass authentication and gain administrative access to susceptible systems. The vulnerability, tracked as CVE-2025-37103, carries a CVSS score of 9.8 out of a maximum of 10.0. "Hard-coded login credentials were found in HPE
Avatar
Read More

CISA Adds 3 Flaws to KEV Catalog, Impacting AMI MegaRAC, D-Link, Fortinet

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three security flaws, each impacting AMI MegaRAC, D-Link DIR-859 router, and Fortinet FortiOS, to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The list of vulnerabilities is as follows - CVE-2024-54085 (CVSS score: 10.0) - An authentication bypass by spoofing
Avatar
Read More