. | . |
Ransomware gang goes offline, prompting questions by AFP Staff Writers Washington (AFP) July 13, 2021 A Russian-based hacker group blamed for a massive ransomware attack went offline Tuesday, sparking speculation about whether the move was the result of a government-led action. The "dark web" page of the group known as REvil disappeared some two weeks after an attack which crippled networks of hundreds of companies worldwide and prompted a ransom demand of $70 million. "REvil has seemingly vanished from the dark web, as its website has gone offline," tweeted Allan Liska, a security researcher with the firm Recorded Future, who noted that the site had been unresponsive from around 0500 GMT. The news comes after US President Joe Biden repeated a warning to his Russian counterpart Vladimir Putin late last week about harboring cybercriminals while suggesting Washington could take action in the face of growing ransomware attacks. Analysts in the past have suggested that the US military's Cyber Command has the capability to strike back at hackers in the face of threats to national security, but there was no official word on any such action. "The situation is still unfolding, but evidence suggests REvil has suffered a planned, concurrent takedown of their infrastructure, either by the operators themselves or via industry or law enforcement action," John Hultquist of Mandiant Threat Intelligence said in an emailed statement. "If this was a disruption operation of some kind, full details may never come to light." Brett Callow of the security firm Emsisoft also pointed to unanswered questions. "Whether the outage is the result of action taken by law enforcement is unclear," Callow said. "If law enforcement has managed to disrupt the gang's operations, that would obviously be a good thing, but could create problems for any companies whose data is currently encrypted. They'd not have the option of paying REvil for the key needed to decrypt their data." James Lewis, head of technology and public policy at the Washington-based Center for Strategic & International Studies, said the site may be down for a number of reasons including pressure from Russian authorities. "I don't think it was us," he said. Liska noted that the site's ownership had not been changed, making a domain seizure less likely. "This could suggest these are self-directed takedowns (too early to tell)," he said. The unprecedented attack targeting the US software firm Kaseya affected an estimated 1,500 businesses. The Kaseya attack, which was reported July 2, shut down a major Swedish supermarket chain and ricocheted around the world, impacting businesses in at least 17 countries, from pharmacies to gas stations, as well as dozens of New Zealand kindergartens.
Ransomware-hit software firm says servers restored Washington (AFP) July 12, 2021 A US software firm said Monday it fully restored its servers more than a week after being hit by a ransomware attack that crippled hundreds of companies worldwide. The Miami-based IT firm Kaseya said it had fully restored its signature VSA software operations, which are used to manage networks of computers and printers. "The restoration of services is now complete," the company's update said, following several days of delays and partial restoration over the weekend. "We will continue to post ... read more
|
|
The content herein, unless otherwise known to be public domain, are Copyright 1995-2024 - Space Media Network. All websites are published in Australia and are solely subject to Australian law and governed by Fair Use principals for news reporting and research purposes. AFP, UPI and IANS news wire stories are copyright Agence France-Presse, United Press International and Indo-Asia News Service. ESA news reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. All articles labeled "by Staff Writers" include reports supplied to Space Media Network by industry news wires, PR agencies, corporate press officers and the like. Such articles are individually curated and edited by Space Media Network staff on the basis of the report's information value to our industry and professional readership. Advertising does not imply endorsement, agreement or approval of any opinions, statements or information provided by Space Media Network on any Web page published or hosted by Space Media Network. General Data Protection Regulation (GDPR) Statement Our advertisers use various cookies and the like to deliver the best ad banner available at one time. All network advertising suppliers have GDPR policies (Legitimate Interest) that conform with EU regulations for data collection. By using our websites you consent to cookie based advertising. If you do not agree with this then you must stop using the websites from May 25, 2018. Privacy Statement. Additional information can be found here at About Us. |