{"id":21162,"date":"2023-02-05T10:17:01","date_gmt":"2023-02-05T18:17:01","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/02\/05\/news-14894\/"},"modified":"2023-02-05T10:17:01","modified_gmt":"2023-02-05T18:17:01","slug":"news-14894","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2023\/02\/05\/news-14894\/","title":{"rendered":"Finland&#8217;s Most-Wanted Hacker Nabbed in France"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Sun, 05 Feb 2023 16:14:13 +0000<\/strong><\/p>\n<p><strong>Julius &#8220;Zeekill&#8221; Kivim\u00e4ki,<\/strong> a 25-year-old Finnish man charged with extorting a local online psychotherapy practice and leaking therapy notes for more than 22,000 patients online, was arrested this week in France. A notorious hacker convicted of perpetrating tens of thousands of cybercrimes, Kivim\u00e4ki had been in hiding since October 2022, when he failed to show up in court and Finland issued an international warrant for his arrest.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-61773\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted.png\" alt=\"\" width=\"2936\" height=\"1398\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted.png 2936w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-768x366.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-1536x731.png 1536w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-2048x975.png 2048w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted-782x372.png 782w\" sizes=\"auto, (max-width: 2936px) 100vw, 2936px\" \/><\/p>\n<p>In late October 2022, Kivim\u00e4ki was charged (and &#8220;arrested in absentia,&#8221; according to the Finns) with attempting to extort money from the<strong>\u00a0Vastaamo Psychotherapy Center<\/strong>. In that breach, which occurred in October 2020, a hacker using the handle &#8220;Ransom Man&#8221; threatened to publish patient psychotherapy notes if Vastaamo did not pay a six-figure ransom demand.<\/p>\n<p>Vastaamo refused, so Ransom Man shifted to extorting individual patients &#8212; sending them targeted emails threatening to publish their therapy notes unless paid a 500-euro ransom.<\/p>\n<p>When Ransom Man found little success extorting patients directly, they uploaded to the dark web a large compressed file containing all of the stolen Vastaamo patient records.<\/p>\n<p>But as <a href=\"https:\/\/krebsonsecurity.com\/2022\/11\/hacker-charged-with-extorting-online-psychotherapy-service\/\" target=\"_blank\" rel=\"noopener\">documented by KrebsOnSecurity in November 2022<\/a>, security experts soon discovered Ransom Man had mistakenly included an entire copy of their home folder, where investigators found many clues pointing to Kivim\u00e4ki&#8217;s involvement. From that story:<\/p>\n<p>&#8220;Among those who grabbed a copy of the database was <strong>Antti Kurittu<\/strong>, a team lead at\u00a0<strong>Nixu Corporation<\/strong> and a former criminal investigator. In 2013, Kurittu worked on an investigation involving Kivim\u00e4ki\u2019s use of the Zbot botnet, among other activities Kivim\u00e4ki engaged in as a member of the hacker group <a href=\"https:\/\/krebsonsecurity.com\/2015\/02\/webnic-registrar-blamed-for-hijack-of-lenovo-google-domains\/\" target=\"_blank\" rel=\"noopener\">Hack the Planet<\/a> (HTP).&#8221;<\/p>\n<p>\u201cIt was a huge opsec [operational security] fail, because they had a lot of stuff in there \u2014 including the user\u2019s private SSH folder, and a lot of known hosts that we could take a very good look at,\u201d Kurittu told KrebsOnSecurity, declining to discuss specifics of the evidence investigators seized. \u201cThere were also other projects and databases.\u201d<\/p>\n<p>According to the <a href=\"https:\/\/actu.fr\/ile-de-france\/courbevoie_92026\/courbevoie-appelee-pour-violences-conjugales-la-police-arrete-un-criminel-international_57121782.html\" target=\"_blank\" rel=\"noopener\">French news site actu.fr<\/a>, Kivim\u00e4ki was arrested around 7 a.m. on Feb. 3, after authorities in <a href=\"https:\/\/en.wikipedia.org\/wiki\/Courbevoie\" target=\"_blank\" rel=\"noopener\">Courbevoie<\/a> responded to a domestic violence report. Kivim\u00e4ki had been out earlier with a woman at a local nightclub, and later the two returned to her home but reportedly got into a heated argument.<\/p>\n<p>Police responding to the scene were admitted by another woman &#8212; possibly a roommate &#8212; and found the man inside still sleeping off a long night. When they roused him and asked for identification, the 6&#8242; 4&#8243; blonde, green-eyed man presented an ID that stated he was of Romanian nationality.<\/p>\n<p>The French police were doubtful. After consulting records on most-wanted criminals, they quickly identified the man as Kivim\u00e4ki and took him into custody.<span id=\"more-62563\"><\/span><\/p>\n<p>Kivim\u00e4ki initially gained notoriety as a self-professed member of the <a href=\"https:\/\/krebsonsecurity.com\/tag\/lizard-squad\/\" target=\"_blank\" rel=\"noopener\">Lizard Squad<\/a>, a mainly low-skilled hacker group that specialized in DDoS attacks. But American and Finnish investigators say Kivim\u00e4ki&#8217;s involvement in cybercrime dates back to at least 2008, when he was introduced to a founding member of what would soon become HTP.<\/p>\n<p>Finnish police said Kivim\u00e4ki also used the nicknames &#8220;Ryan&#8221;, &#8220;RyanC&#8221; and &#8220;Ryan Cleary&#8221; (Ryan Cleary was actually a member of a rival hacker group &#8212; <a href=\"https:\/\/en.wikipedia.org\/wiki\/LulzSec\" target=\"_blank\" rel=\"noopener\">LulzSec<\/a> &#8212; who was sentenced to prison for hacking).<\/p>\n<p>Kivimaki and other HTP members were involved in mass-compromising web servers using known vulnerabilities, and by 2012 Kivim\u00e4ki&#8217;s alias Ryan Cleary was selling access to those servers in the form of a DDoS-for-hire service. Kivim\u00e4ki was 15 years old at the time.<\/p>\n<div id=\"attachment_62569\" style=\"width: 633px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-62569\" loading=\"lazy\" class=\"size-full wp-image-62569\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2023\/02\/ryancddos.png\" alt=\"\" width=\"623\" height=\"588\" \/><\/p>\n<p id=\"caption-attachment-62569\" class=\"wp-caption-text\">The DDoS-for-hire service allegedly operated by Kivim\u00e4ki in 2012.<\/p>\n<\/div>\n<p>In 2013, investigators going through devices seized from Kivim\u00e4ki found computer code that had been used to crack more than 60,000 web servers using a previously unknown vulnerability in <strong>Adobe&#8217;s ColdFusion<\/strong> software.<\/p>\n<p>KrebsOnSecurity detailed the work of HTP in September 2013, after the group <a href=\"https:\/\/krebsonsecurity.com\/2013\/09\/data-broker-giants-hacked-by-id-theft-service\/\" target=\"_blank\" rel=\"noopener\">compromised servers inside data brokers LexisNexis, Kroll, and Dun &amp; Bradstreet<\/a>.<\/p>\n<p>The group used the same ColdFusion flaws <a href=\"https:\/\/krebsonsecurity.com\/2013\/10\/data-broker-hackers-also-compromised-nw3c\/\" target=\"_blank\" rel=\"noopener\">to break into the National White Collar Crime Center (NWC3)<\/a>, a non-profit that provides research and investigative support to the <strong>U.S. Federal Bureau of Investigation<\/strong> (FBI).<\/p>\n<p>As KrebsOnSecurity reported at the time, this small ColdFusion botnet of data broker servers was being controlled by the same cybercriminals who&#8217;d assumed control over <strong>ssndob[.]ms<\/strong>, which operated one of the underground&#8217;s most reliable services for obtaining Social Security Number, dates of birth and credit file information on U.S. residents.<\/p>\n<p>Multiple law enforcement sources told KrebsOnSecurity that Kivim\u00e4ki was responsible for making <a href=\"http:\/\/www.forbes.com\/sites\/insertcoin\/2014\/08\/24\/sony-online-entertainment-presidents-flight-diverted-by-psn-hackers-bomb-threat\/\" target=\"_blank\" rel=\"noopener\">an August 2014 bomb threat<\/a>\u00a0against former\u00a0<strong>Sony Online Entertainment President John Smedley<\/strong> that grounded an American Airlines plane. That incident was widely reported to have started with a tweet from the Lizard Squad, but Smedley and others said it started with a call from Kivim\u00e4ki.<\/p>\n<p class=\"p1\">Kivim\u00e4ki\u00a0also was involved in calling in multiple fake bomb threats and \u201cswatting\u201d incidents \u2014 reporting fake hostage situations at an address to prompt a heavily armed police response to that location.<\/p>\n<p>Kivim\u00e4ki&#8217;s apparent indifference to hiding his tracks drew the interest of Finnish and American cybercrime investigators, and soon Finnish prosecutors charged him with an array of cybercrime violations. At trial, prosecutors presented evidence showing he&#8217;d used stolen credit cards to buy luxury goods and shop vouchers, and participated in a money laundering scheme that he used to fund a trip to Mexico.<\/p>\n<p>Kivim\u00e4ki was ultimately convicted of orchestrating more than 50,000 cybercrimes. But largely because he was still a minor at the time (17) , he was given a 2-year suspended sentence and ordered to forfeit EUR 6,558.<\/p>\n<p>As <a href=\"https:\/\/krebsonsecurity.com\/2015\/07\/finnish-decision-is-win-for-internet-trolls\/\" target=\"_blank\" rel=\"noopener\">I wrote in 2015 following Kivim\u00e4ki&#8217;s trial<\/a>:<\/p>\n<blockquote>\n<p>&#8220;The danger in such a decision is that it emboldens young malicious hackers by reinforcing the already popular notion that there are no consequences for cybercrimes committed by individuals under the age of 18.<\/p>\n<p>Kivim\u00e4ki is now crowing about the sentence; He\u2019s changed the description on his Twitter profile to \u201cUntouchable hacker god.\u201d The Twitter account for the Lizard Squad tweeted the news of Kivim\u00e4ki\u2019s non-sentencing triumphantly: \u201cAll the people that said we would rot in prison don\u2019t want to comprehend what we\u2019ve been saying since the beginning, we have free passes.\u201d<\/p>\n<\/blockquote>\n<p>Something tells me Kivim\u00e4ki won&#8217;t get off so easily this time, assuming he is successfully extradited back to Finland. A statement by the Finnish police says they are seeking Kivim\u00e4ki&#8217;s extradition and that they expect the process to go smoothly.<\/p>\n<p>Kivim\u00e4ki could not be reached for comment. But he has been <a href=\"https:\/\/www.reddit.com\/user\/AleksanteriKivimaki\/\" target=\"_blank\" rel=\"noopener\">discussing his case on Reddit<\/a> using his legal first name &#8212; <strong>Aleksanteri<\/strong> (he stopped using his middle name Julius when he moved abroad several years ago). In a post dated Jan. 31, 2022, Kivim\u00e4ki responded to another Finnish-speaking Reddit user who said they were a fugitive from justice.<\/p>\n<p>&#8220;Same thing,&#8221; Kivim\u00e4ki replied. &#8220;Shall we start some kind of club? A support organization for wanted persons?&#8221;<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2023\/02\/finlands-most-wanted-hacker-nabbed-in-france\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/11\/kikmaki-wanted.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Sun, 05 Feb 2023 16:14:13 +0000<\/strong><\/p>\n<p>Julius &#8220;Zeekill&#8221; Kivim\u00e4ki, a 25-year-old Finnish man charged with extorting a local online psychotherapy practice and leaking therapy notes for more than 22,000 patients online, was arrested this week in France. A notorious hacker convicted of perpetrating tens of thousands of cybercrimes, Kivim\u00e4ki had been in hiding since October 2022, when he failed to show up in court and Finland issued an international warrant for his arrest.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[28511,27899,28512,27900,12086,16696,28513,28514,27905],"class_list":["post-21162","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-antti-kurittu","tag-hack-the-planet","tag-htp","tag-julius-kivimaki","tag-lizard-squad","tag-neer-do-well-news","tag-ryan-cleary","tag-vastaamo-psychotherapy-center","tag-zeekill"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=21162"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21162\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=21162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=21162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=21162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}