Europol shuts down VPN used by cybercriminal groups

artistic representation of a hacker
Image credit: Shutterstock (Image credit: Shutterstock)

A VPN service frequently used by cybercriminals to launch ransomware attacks and spread malware online has been taken down as part of a joint operation between Europol and law enforcement authorities from 10 different countries.

On January 17, disruptive actions took place in a coordinated manner in Germany, the Netherlands, Canada, the Czech Republic, France, Hungary, Latvia, Ukraine the US and the UK as law enforcement from each country seized or disrupted 15 servers used to host VPNLab.net.

Europol's European Cybercrime Centre (EC3) provided support for the operation through its Analysis Project 'CYBORG' which organized over 60 coordination meetings and three in-person workshops while also providing both analytical and forensic support.

Head of the EC3, Edvardas Šileris explained in a press release how data gathered in this operation will be used to help Europol find its next target, saying:

“The actions carried out under this investigation make clear that criminals are running out of ways to hide their tracks online. Each investigation we undertake informs the next, and the information gained on potential victims means we may have pre-empted several serious cyberattacks and data breaches.”

VPNLab Domain Seized

(Image credit: Europol)

A VPN for cybercriminals

First established in 2008, VPNLab.net provided VPN services based on OpenVPN and utilized 2048-bit encryption to provide its customers with online anonymity for as little as $60 per year. In addition to a regular VPN, the site also provided a double VPN where internet traffic would pass through multiple VPN servers before arriving at its destination.

According to Europol, law enforcement first took interest in VPNLab after multiple investigations revealed that cybercriminals were using the service for illicit activities including malware distribution. Meanwhile, other cases showed that the service was used to set up infrastructure and communications behind ransomware campaigns. In a press release, Ukraine's cyberpolice revealed that VPNLab was used in at least 150 ransomware attacks.

While VPNLab has now been shut down, the owners and operators of the service have yet to be identified, charged or arrested. However, data seized from the service's servers could hold valuable evidence on who was behind the operation.

At the same time, law enforcement plans to comb through VPNLab's customer data with the aim of identifying additional ransomware affiliates.

We've also featured the best endpoint security software and best identity theft protection

Via BleepingComputer

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Cyber crime concept with man in handcuffs
Global police operation takes down major cybercrime and hacking forums
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Ransomware
8base ransomware site taken down in global police operation
Homepage of CloudFlare website on the display of PC, url - CloudFlare.com.
"Network blocking is never going to be the solution" – Cloudflare slams anti-piracy tactics
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
China-linked cyberespionage group PlushDaemon used South Korean VPN service to inject malware
Representational image of a cybercriminal
US, UK crack down on Russian bulletproof hosting service ZServers for LockBit partnership
Latest in VPN Privacy & Security
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Tor
What is Onion over VPN?
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
PrivadoVPN running on an iPhone during TechRadar's VPN tests
Why PrivadoVPN Free is still the best free VPN for streaming
Latest in News
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Intel Lunar Lake concept
Intel's Panther Lake processors won't arrive until Q1 2026 - corroborates previous delay rumors despite former Intel CEO's promise of 2025 launch