Skip naar inhoud

REvil ransomware crew drops offline, reasons murky

Wilt u deze bijdrage aanbevelen? Dat kan via:

The REvil ransomware operation appears to have gone dark, but claims about its demise are almost certainly exaggerated
Dark web infrastructure used by the REvil (aka Sodinokibi) ransomware syndicate dropped offline on Tuesday 13 July, but there is as yet no clarity over why, leaving the security community at a loss to understand exactly what happened.

At the time of writing, there are several equally plausible scenarios behind the REvil gang’s sudden disappearance. It could be as simple a matter as a technical problem, or an internal bust-up between its operators.

The gang members could also be lying low in an attempt to avoid being the subject of retaliation by law enforcement following their recent high-profile attack on Kaseya, or they could even have already been compromised and arrested.

Ransomware crews also frequently disappear and retool before making a grand re-entrance with a new project – REvil is in fact thought to have done this before, the actors behind it likely being the same as those behind an old ransomware strain known as GandCrab. There is also a possibility that the gang has cashed out and run off.

In any case, the gang’s disappearance is cause for muted celebration for the time being, as Katie Nickels, intelligence director at Red Canary, said.

“I don’t know what this means, but regardless, I’m happy,” she said. “If it’s a government takedown – awesome, they’re taking action. If the actors voluntarily went quiet – excellent, maybe they’re scared. It’s still important to remember that this doesn’t solve ransomware.”

John Vestberg, CEO and co-founder of Clavister, added: “Although it is unclear the exact reason why REvil ransomware websites have gone offline, it is a positive step in the fight against these cyber criminal gangs.

“That said, it is only a matter of time before another ransomware incident takes place. The attack on Kaseya was the latest in a line of incidents that have caused wide-spread havoc – from the Colonial Pipeline to the JBS food production plant in the US. This is not the time for organisations to get complacent.”

Read more about REvil’s activity

  • REvil or Sodinokibi ransomware activity is higher than ever, but its success appears to be relative, with some affiliates prepared to dramatically cut their prices.
  • Last week JBS USA said a REvil ransomware attack was resolved, and all facilities were fully operational, but now the company confirmed it paid a huge ransom.
  • A record-breaking double-extortion cyberattack saw REvil gang exfiltrate financial data from Taiwan-based PC manufacturer Acer.

In the best-case scenario, the downing of REvil is the result of a coordinated offensive raid by law enforcement in the gang’s home country – almost certainly Russia – which would suggest that recent discussions between US president Joe Biden and his Russian counterpart Vladimir Putin were more fruitful than anyone in the cyber community had dared hope.

And this scenario may contain an element of truth. Citing a source with alleged links to the REvil gang, the BBC earlier reported suggestions that US authorities had disrupted parts of the gang’s infrastructure, forcing them to shutter their operation. The source also said the gang had been under pressure from Russian authorities over the extent of its activity. These claims should be treated very sceptically for now.

“If the outage is the result of an offensive response, this then sends a new message to these groups that they have a limited window in which to work,” said Exabeam chief security strategist Steve Moore.

ESET’s Jake Moore said that in other cases, the scale and breadth of improving law enforcement tactics was clearly now bringing more success in disrupting malicious actors.

“Although the detail in such law enforcement tactics still remains unknown to the public, it highlights that the police are continuing to grow in their operations and fight from different angles,” he said. “However, this setback for REvil is unlikely to deter them completely. If anything, it may spur them on more.”

Lees ook:

Help een jongere zijn studie door, doneer nu je oude laptop.

Het zal u vast nog niet ontgaan zijn, maar door de hoge inflatie is alles duurder geworden. In sommige gevallen zelfs te duur, zoals een nieuwe laptop voor een studie.

Wat wil en wenst de ontwikkelaar?

In een krappe ict-arbeidsmarkt is het voor werkgevers interessant te weten wat er onder ontwikkelaars leeft. Bedrijven die de juiste tools bieden, hebben een streepje voor. Een internationaal onderzoek onder ruim zeventigduizend ontwikkelaars uit de Stack Overflow-community geeft inzicht in de trends. Dit rapport is bij recruiters dan ook niet onopgemerkt gebleven. Ze krijgen zo een beeld van hoe developers leren en meer kennis vergaren, welke tools ze gebruiken en waaraan ze behoefte hebben.

TNO: Europa kan tech-overmacht VS en China doorbreken

Zet vol in op de ontwikkeling van 6G, maak Gaia-X volwassen, loop voorop met edge computing en omarm open technologie. Dit zijn enkele aanbevelingen van TNO om in Europa de overheersing van Big Tech en Chinese (5G-)bedrijven te doorbreken.

Subpostmaster campaigning forces government to set up compensation scheme and make interim payments

Subpostmaster campaign group is a step closer to achieving what it was originally set up to do as government launches compensation scheme for its members who did not receive fair payouts

Advies: wacht met 3,5 GHz tot Inmarsat weg is

Het duurt waarschijnlijk tot eind 2023 voordat de 3,5-GHz-frequentieband beschikbaar komt voor openbare mobiele-communicatiediensten. Er is weliswaar veel vraag naar extra frequentieruimte, maar op de daarvoor afgesproken 3,5-GHz-band kan dat storen met noodoproepen van de lucht- en zeevaart. Het ministerie krijgt het advies te wachten totdat satellietbedrijf Inmarsat is verhuisd van het Friese Burum naar Griekenland.

Na sase komt sse (security service edge)

Security service edge (sse) is de evolutie van het sase-framework van Gartner. Door de letter ‘A’ (voor ’access) te verwijderen, wordt duidelijk dat het netwerk niet langer wordt beschouwd als onderdeel van een beveiligingsoplossing. Het is slechts het mechanisme dat de datastromen naar het security- en controleplatform transporteert.

Wilt u deze bijdrage aanbevelen? Dat kan via:

Klaar voor de beste oplossing voor uw IT & ICT-situatie?

Ik heb mijn wachtwoord gewijzigd in “onjuist.” Dus wanneer ik vergeet wat het is, zal de computer zeggen: “Uw wachtwoord is onjuist.”