World

US accuses Venezuela doctor of selling ransomware to cybercriminals

Moises Luis Zagala, 55, was both cardiologist and malicious programmer, say prosecutors

Updated 4 years ago · Published on 17 May 2022 10:05AM

US accuses Venezuela doctor of selling ransomware to cybercriminals
According to the Brooklyn district attorney’s office, the ransomware encrypts information on computers that have been hacked, then the attackers demand money to decrypt it. – AFP pic, May 17, 2022

NEW YORK – A French-Venezuelan cardiologist was accused yesterday by the United States of selling ransomware to cybercriminals and instructing them on how to extort money from the victims they hacked. 

The Brooklyn district attorney’s office said Moises Luis Zagala, 55, who lives in the Venezuelan city of Ciudad Bolivar, “not only created and sold ransomware products to hackers, but also trained them in their use”. 

It said the French-Venezuelan doctor “sold the tools for conducting ransomware attacks, trained the attackers about how to extort victims, and then boasted about successful attacks, including by malicious actors associated with the government of Iran”.

The ransomware would encrypt information on the computers that had been hacked, then the attackers would demand money to decrypt it. 

One of the first products developed by Zagala was a data hijacking programme called “Jigsaw v. 2”, which had a “doomsday” counter that kept track of the times the user had tried to destroy it.

“If the user kills the ransomware too many times, then it’s clear he won’t pay so better erase the whole hard drive,” Zagala instructed his clients, according to the US authorities.

In early 2019, Zagala began advertising his new tool on the web, a “Private Ransomware Builder” which he named “Thanos” after the Marvel Comics villain responsible for destroying half of life in the universe, as well as Thanatos in Greek mythology, associated with death. 

The “multi-tasking doctor”, as the Brooklyn DA described him, allowed criminals to either buy the programme – and create their own customised ransom notes – or to join an “affiliate programme” to gain access to the programme in exchange for a share of the ill-gotten gains, which could be paid in cryptocurrency or regular cash. 

His preferred aliases were “Aesculapius”, referring to the ancient Greek god of medicine, and “Nosophoros”, which means "sickness" in Greek.

Zagala allegedly boasted in specialised hacker forums that the Thanos programme was practically undetectable by antivirus programmes and that once the encryption was finished the programme would self-delete, making it almost impossible for the victim to be able to detect it and retrieve their documents. 

Zagala even asked his clients “if you have time and it’s not too much trouble” to rate their experience online.  

If found guilty, he could be sentenced to 10 years in jail. – AFP, May 17, 2022

Related News

Malaysia / 4mth

SMEs most vulnerable to data breaches and hacking – expert

Malaysia / 3y

Unauthorised server access caused AirAsia data leak: Fahmi

World / 4y

Severe cyberattack exposes personal data of entire Swiss town

Business / 4y

Massive ransomware attack may have hit 1,000 businesses

World / 5y

Meatpacking giant JBS says paid US$11 mil to hackers in ransomware attack

World / 5y

Biden says ‘looking’ at retaliation with Russia over cyberattack

Spotlight

Malaysia

Bersatu-PH tie-up a possibility as coalition seeks Malay support, analyst says

By Alfian Z.M. Tahir

Malaysia

Woman molested on her way home from work (video)

Malaysia

Court allows Daim's daughter to permanently keep passport

Malaysia

Santiago pokes holes in data centre hype, asks: Who really benefits?

By Alfian Z.M. Tahir

Malaysia

Jeweller vows to pursue Rosmah until ‘every penny’ is recovered as RM67.5m battle enters enforcement phase

Malaysia

Ambulance carrying two injured men crashes en route to hospital after MPV collision in Besut

Malaysia

Man blames 'lack of love' for sexual assault on teens

Business

BNM's OPR to stay at 2.75 pcent in 2026 amid strong domestic demand - Kenanga IB

Malaysia

Missing jewellery: Rosmah ordered to pay RM67.5 million

You may be interested

World

US escalates Iran campaign with fresh strikes as Trump threatens far broader military action

World

Malaysia - Japan deepen strategic economic ties with landmark LNG deal and local currency push

World

US-Iran escalates direct strikes as Trump warns of “heavy bombing” unless peace deal is signed

World

Xi–Kim summit spotlights closer ties; Silence on nuclear issue signals shift in China’s North Korea policy

World

Philippine earthquake displaces 32,000 people, kills at least 37

World

Oil prices surge as US-Iran strikes intensify

World

HRW: Private military contractors deployed to Sudan to support RSF

By Alfian Z.M. Tahir

World

Bill Gates: ‘Epstein attempted to exploit my personal life’