News: 1634899391

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Unhappy customers and their own tricks used against them, REvil ransomware gang reportedly pulled offline by 'multi-country' operations

(2021/10/22)


As we noted [1]a few days back , notorious ransomware gang REvil "disappeared" again this week. Recent reports have now shed light on why that may be.

The REvil leaks blog, known as Happy Blog, was made inaccessible on October 17, the same day one of its operators announced the group was shutting down due to a hijacking of their domain on Russian forum XSS, security vendor Flashpoint [2]said at the time.

Now we may know why. Reuters [3]reported the cybergang was taken down by a multi-country operation.

[4]

According to VMWare cybersecurity strategy boss Tom Kellermann, who also advises the US Secret Service on cybercrime investigations, said that police and intelligence agencies across the world worked together to stop the group's operations. He told the newswire: "The FBI, in conjunction with Cyber Command, the Secret Service and like-minded countries, have truly engaged in significant disruptive actions against these groups." He added: "REvil was top of the list."

[5]

[6]

According to the report, law enforcement and intelligence specialists managed to gain access to REvil's computer network infrastructure this week, thereby gaining partial control of servers. When servers were rebooted this last time around, some systems were already controlled by the government, thus using REvil's own typical approach against them.

It's not the first time it has vanished – the group, which was responsible for the [7]Colonial Pipeline ransomware attack last May, among many others, went offline in July and the main spokesman, "Unknown", disappeared.

[8]

REvil later returned, but according to Flashpoint, they left many in the ransomware criminal community suspicious due to behaviour such as offering 90 per cent "commissions" and aggressively recruiting.

[9]REvil ransomware gang's websites vanish soon after Kaseya fiasco, Uncle Sam threatens retaliation

[10]Email phishing crapcannon operators TA505 are back from the dead, researchers warn

[11]Acer servers cracked in India and Taiwan – including systems with customer data

[12]BlackMatter ransomware gang will target agriculture for its next harvest – Uncle Sam

[13]When criminals go corporate: Ransomware-as-a-service, bulk discounts and more

Business for REvil was already looking a bit shaky with unhappy customers giving their own negative Tripadvisor-style reviews. Back in September, Flashpoint [14]reported some of REvil's customers suspected there were backdoors that allow REvil to restore encrypted files themselves in the gang's rentable malware. There were other complaints too – about the corporate-style threat actor's behaviour and reluctance to negotiate with their ransomware-as-a-service customers.

In addition to the Colonial Pipeline hack, REvil's notoriety extends to IT management software provider [15]Kaseya , which unwittingly passed on the blessing of malware through its products, as well as Apple supplier [16]Quanta .

Tom Robinson, chief scientist and co-founder at crypto transaction monitoring firm Elliptic told The Reg in a statement this morning that his organisation believed $7m in bitcoin held by the DarkSide ransomware group was moved yesterday. "These funds had remained dormant since the group shut down on May 13," he said, adding: "DarkSide has been strongly linked to REvil, with the ransomware groups sharing similarly structured ransom notes and using the same code." Robinson said:

Beginning at 7am GMT [on 21 October], the funds, now worth $7m, were moved through a series of new wallets over the course of several hours, with small amounts being "peeled" off at each step. This is a common money laundering technique, used to attempt to make the funds more difficult to track and to aid their conversion into fiat currency through exchanges. The process is ongoing, but small amounts of the funds have already been sent to known exchanges.

About a week ago, over 30 countries and the EU [17]met on Zoom, notably without Russia, to chat about what could be done about these dang ransomware threats. It seems REvil's downfall was already in the works. ®

Get our [18]Tech Resources



[1] https://www.theregister.com/2021/10/19/ta505_email_phishing_threat_group_returns/

[2] https://www.flashpoint-intel.com/blog/revil-disappears-again/

[3] https://www.reuters.com/technology/exclusive-governments-turn-tables-ransomware-gang-revil-by-pushing-it-offline-2021-10-21/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YXLgPQ7Y7WcOEoZ8ZGRUYQAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXLgPQ7Y7WcOEoZ8ZGRUYQAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YXLgPQ7Y7WcOEoZ8ZGRUYQAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YXLgPQ7Y7WcOEoZ8ZGRUYQAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2021/07/13/revil_ransomware_shuts/

[10] https://www.theregister.com/2021/10/19/ta505_email_phishing_threat_group_returns/

[11] https://www.theregister.com/2021/10/20/acer_india_taiwan_data_leaks/

[12] https://www.theregister.com/2021/10/19/cisa_blackmatter_agricutlure/

[13] https://www.theregister.com/2021/10/11/ransomware_as_a_service/

[14] https://www.theregister.com/2021/09/29/revil_customers_complain_about_backdoors/

[15] https://www.theregister.com/2021/07/05/kaseya_vsa_update/

[16] https://www.theregister.com/2021/04/21/quanta_confirms_ransomware/

[17] https://www.theregister.com/2021/10/14/virtual_counter_ransomware_initiative_meeting/

[18] https://whitepapers.theregister.com/



REvil's downfall

Pascal Monett

If I'm not mistaken, it's only the servers and command structure that went down.

There haven't been any arrests.

So these people are free to set up a new command structure. I'm sure they have backups. They'll be back online shortly.

I applaud the takedown obviously, but until those scum are in jail, they'll be back.

Re: REvil's downfall

Version 1.0

I'm guessing that law enforcement sent REvil a malware infection to take control of their systems, but I would bet that REvil have backups so let's watch out for the future, will a new gang called livER appear sending out app to run on systems to "prevent" infections called "Ma Lawer" ....

Re: REvil's downfall

General Purpose

>They'll be back online shortly.

But how will they prove they're genuine?

Re: REvil's downfall

Snake

It would be reasonable to believe that they admin'ed their servers through an onion-routed interface, at least if they had a drop of intelligence they would have. This makes finding the humans behind the tech a lot harder, maybe if we give them more time to dive into the systems they penetrated we can hope for arrests in the future.

fight fire with fire

Anonymous Coward

I enjoy greatly how the law-enforcement agencies have taken to using conspiracy theories to undermine criminals 'creds'. It's quite hilarious to see gangs being frustrated by their customers' distrust towards gangs' legitimacy after 'resurrection', PLUS those, totally anonymous, unhappy reviews. Ironically, as with any conspiracy theories, it's impossible to separate facts from fiction (ever!) and refute the theories, and I'm pretty sure law-enforcement agencies had a finger in sowing this mistrust.

Re: fight fire with fire

Sixtiesplastictrektableware

Agree. Looks like the same old 'infiltrate the intruders' approach, though. Time honoured 'cause it always works.

Well, it works after some trial and error. The formation of CSIS in Canadaland comes to mind.

People taking it upon themselves to commit crimes for profit would appear to be quick to incite in the right/wrong company. Those that are bad at it, anyways.

OR...

blue dragon

They abandoned everything and are in the planning phase to leverage the gigabyte master key theft. Just when we thought things were bad, in the words of the great scientist Sam Beckett; "Oh Boy"

Rhetoric

Clausewitz 4.0

It is all about rhetoric. They ramper their cyber capabilities while trying to take down the opponent's cyber capabilities.

Luckily we have better brains and commanders around here. And encrypted backups.

Blackjack

They meet on Zoom?

That Zoom? The one that's not private or safe?

That's kind of funny.

Clausewitz 4.0

We shall suppose quasi-normal talks are held there. Important discussions are done always behind closed-doors, in-person. With "bluetooth" disabled.

Just deserts.

Patched Out

It would be really great if the law enforcement team that managed to infiltrate their infrastructure also managed to encrypt all of their backups prior to shutting them down. Now THAT would be justice.

"Notably without Russia"

Snake

Big surprise. I was going to ask about Russia's involvement, expecting a "null" on that.

Re: "Notably without Russia"

Clausewitz 4.0

Notably, Russia was not called by the other belligerent parties. Russia alleges they sent over 40 requisitions of cyber-threats detected, but all unanswered from USA. Do you see the trap? No cooperation to disrupt operations from A, but they need to disrupt operations from B.

Re: "Notably without Russia"

WolfFan

No one believes what Russia alleges, in the unlikely event that there’s some truth to even one of those allegations, no one cares.

Re: "Notably without Russia"

Clausewitz 4.0

You usually do not need to believe in anyone. But you should believe in serious folks with physical material and already demonstrated capabilities.

TrevorH

After Kaseya it appears that REvil got out of the ransomware business. If the recent attacks on VoIP infrastructure are to be believed they've moved into plain extortion instead - "Send us 10 BTC or we will DDoS your business to death".

"One lawyer can steal more than a hundred men with guns."
-- The Godfather