Ransomware Giant REvil’s Sites Disappear
#1
Information 
Quote:All of REvil’s Dark Web sites slipped offline as of early Tuesday morning, and it’s not clear whether it’s due to the ransomware gang getting busted or whether the threat actors did it on purpose.
 
The REvil ransomware operation, a.k.a. Sodinokibi, uses both clear web and Dark Web sites to negotiate ransoms, leak data, support its backend infrastructure and receive payment from its many victimized organizations. That victims list has recently grown with the addition of Kaseya and its many managed service provider (MSP) customers, as well as the global meat supplier JBS Foods,

All of REvil’s sites went offline as of around 1 a.m. It doesn’t mean that the notorious gang has been shut down, as one cybersecurity expert emphasized – it’s just that all its sites were unreachable, up until at least Tuesday at 2:55 p.m. EDT.
 
One possibility: It could be that the U.S. shut down the servers. Then again, perhaps it was the Russian government. The timing would make sense, given the White House’s saber-rattling at Russia over the ransomware plague. The silenced servers come just a few days after President Biden called President Vladimir V. Putin of Russia and demanded that he shut down ransomware groups attacking American targets.
 
If you don’t, we will, Biden said. On Friday, when a pool of reporters asked the president if the U.S. might attack the servers that Russia-linked cybercriminals have used to hijack American networks, he said, “Yes.”
 
Jake Williams, co-founder and CTO at BreachQuest, told Threatpost that it’s all just speculation at this point, but ransomware gangs operating in Russia “were on borrowed time the second Colonial was hit.” He was referring to the ransomware attack on Colonial Pipeline leading up to Memorial Day Weekend: An attack that was attributed to the ransomware-as-a-service (RaaS) player DarkSide.
 
“The Russian government didn’t care about the cybercrime occurring within its borders, but only so long as it didn’t impact Russia itself,” Williams said in an email. “That has clearly changed – the Russian government can clearly see they are being impacted by the actions of these actors. Whether REvil was taken out of commission by the Russian government, saw the writing on the wall and took infrastructure down, is simply rebranding like so many groups have (likely including REvil itself), or something else, is unknown at this point.”

Read more: Ransomware Giant REvil Disappears | Threatpost
Reply


Forum Jump:


Users browsing this thread:
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AxCrypt 3.0.0.94
AxCrypt 3.0.0.94: ...harlan4096 — 11:41
NVIDIA GeForce Game Ready 596.49 driver
Highlights  Gam...harlan4096 — 11:40
AMD launches six new Ryzen PRO 9000 CPUs...
AMD Ryzen PRO 9000...harlan4096 — 11:39
AMD HDMI 2.1 DSC patches could bring 4K ...
AMDGPU HDMI 2.1 pa...harlan4096 — 11:37
Vulkan 1.4.351 adds six extensions with ...
Khronos releases V...harlan4096 — 11:35

[-]
Birthdays
Today's Birthdays
avatar (38)owysykan
avatar (49)beautgok
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>