REvil ransomware gang's websites vanish soon after Kaseya fiasco, Uncle Sam threatens retaliation
- Reference: 1626205985
- News link: https://www.theregister.co.uk/2021/07/13/revil_ransomware_shuts/
- Source link:
At time of writing, all of REvil's portals and infrastructure – used to negotiate and collect ransom payments, and leak stolen data to encourage victims to cough up before the whole lot is released – have vanished. They've been missing in action since 0100 US Eastern Time, or around 0800 in Moscow. We say Moscow because it's believed REvil is orchestrated by miscreants in Russia. For one thing, it appears to leave computers in the nation alone.
"The REvil leak site is definitely unreachable," Sean Gallagher, Sophos senior threat researcher, told The Register , adding: "The server is likely down.
[1]
"It could be that the server hardware failed, or that it was intentionally taken down, or that someone attacked their host. At this time, there's nothing claiming that law enforcement is responsible. The public internet ransom site was also down last week."
[2]
[3]
On Friday, President Biden had a phone call with Russia's President Putin about the worldwide ransomware epidemic, and afterwards [4]told the press the US was prepared to attack the servers used by ransomware criminals who were targeting American businesses and citizens.
[5]Kaseya restores SaaS, then 'performance issues' force a do-over
[6]With a straight face, Putin agrees to do something about ransomware coming out of Russia, apparently
[7]Report shines light on REvil's depressingly simple tactics: Phishing, credential-stuffing RDP servers... the usual
[8]Ransomware-hit law firm gets court order asking crooks not to publish the data they stole
Extortionware infections have exploded in the past decade, and REvil has had some big scores – such as exploiting installations of [9]Kaseya's IT management software to infect as many as 1,500 businesses in one fell swoop just this month.
Has Team America taken down REvil, perhaps even with Putin's help? It's too early to tell. Ransomware groups are just like any other IT operation and suffer outages as much as anyone else. It's possible that the crew are simply having an issue or are redoing their infrastructure.
The other, and more probable explanation, is that the ransomware crims have simply decided to close down for a while until the heat is off – the [10]Darkside gang behind the Colonial Pipeline ransomware freaked out at the media and law enforcement attention it drew, for instance – and take a summer holiday with their ill-gotten gains to return later, maybe even with a rebrand.
[11]
The Russian-speaking crooks behind the TrickBot botnot are [12]back already with upgrades, by the way, after US Cyber Command, Microsoft, and others [13]tried to take it down.
Ransomware is a huge money-making scheme, thanks to some organizations' willingness to pay to make a problem go away. These miscreants are unlikely to give up voluntarily. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YO4M-eoyawq3W9bL4Eh-dQAAABc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YO4M-eoyawq3W9bL4Eh-dQAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YO4M-eoyawq3W9bL4Eh-dQAAABc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/07/12/in_brief_security/
[5] https://www.theregister.com/2021/07/13/kaseya_update/
[6] https://www.theregister.com/2021/07/12/in_brief_security/
[7] https://www.theregister.com/2021/07/07/revil_tactics_and_multimillion_dollar/
[8] https://www.theregister.com/2021/07/06/ransomware_4_new_square_chambers/
[9] https://www.theregister.com/2021/07/13/kaseya_update/
[10] https://www.theregister.com/2021/05/13/colonial_pipeline_ransom/
[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YO4M-eoyawq3W9bL4Eh-dQAAABc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[12] https://www.bitdefender.com/blog/labs/trickbot-activity-increases-new-vnc-module-on-the-radar
[13] https://www.thedailybeast.com/the-pentagon-tried-to-take-down-these-hackers-theyre-back?scrolla=5eb6d68b7fedc32c19ef33b4
[14] https://whitepapers.theregister.com/
Only if they have done something to piss off the Russian government, and Putin hands them over as a favor to Biden - expecting some type of favor in return.
The US isn't going to kidnap people out of Moscow for this type of crime, knowing that it could create an international incident and risk the rendition team ending up in a Russian Gulag if something goes wrong.
Won't do any good to punish a few individuals. You need to eliminate their safe-haven.
I really hope they were busted
Let's hope they were busted. And on their way to a nice gulag.
So this will take a little pressure of Putin, I expect that someone has had a word with the folks running the website and told them to close it down. That's probably all that's happened and a new site will appear in a while and everyone will say that it's a different bunch. Shutting down the website is not going to eliminate the Ransomware.
I can't help thinking that at some point a few Russians will start drinking in a bar in Moscow or wherever and wake up in an hotel room in a country that has an extradition warrant with the US and the local cops knocking at the door.