Normal view
-
Bitcoin News - Darknet Archives
- Irish Authorities Seize $7.1M in Cryptocurrency Amid Darknet Money Laundering Bust
-
Bitcoin News - Darknet Archives
- Hive Ransomware Network Dismantled by American, European Law Enforcement
Hive Ransomware Network Dismantled by American, European Law Enforcement
Law enforcement authorities from over a dozen countries in Europe and North America have taken part in disrupting the activities of the Hive ransomware group, the U.S. Justice Department and Europol announced. Hive is believed to have targeted various organizations worldwide in the past couple of years, often extorting payments in cryptocurrency.
Captured Decryption Keys Helped Hive Victims Avoid Paying $130 Million in Ransom
Ransomware network Hive, which has had around 1,500 victims in more than 80 countries, has been hit in a months-long disruption campaign, the U.S. Department of Justice (DOJ) and the European Union Agency for Law Enforcement Cooperation (Europol) revealed. A total of 13 nations participated in the operation, including EU member states, the U.K. and Canada.
Hive has been identified as a major cybersecurity threat as the ransomware has been used by affiliated actors to compromise and encrypt data and computer systems of government facilities, oil multinationals, IT and telecom companies in the EU and U.S., Europol said. Hospitals, schools, financial firms, and critical infrastructure have been targeted, the DOJ noted.
It has been one of the most prolific ransomware strains, Chainalysis pointed out, which has collected at least $100 million from victims since its launch in 2021. A recent report by the blockchain forensics company unveiled that revenue from such attacks has decreased last year, with a growing number of affected organizations refusing to pay the demanded ransoms.
According to the announcements by the law enforcement authorities, the U.S. Federal Bureau of Investigation (FBI) penetrated Hiveβs computers in July 2022 and captured its decryption keys, providing them to victims around the world which prevented them from paying another $130 million.
Working with the German Federal Police and the Dutch High Tech Crime Unit, the Bureau has now seized control over the servers and websites that Hive used to communicate with its members and the victims, including the darknet domain where the stolen data was sometimes posted. FBI Director Christopher Wray was quoted as stating:
The coordinated disruption of Hiveβs computer networks β¦ shows what we can accomplish by combining a relentless search for useful technical information to share with victims.
The Hive ransomware was created, maintained and updated by developers while being employed by affiliates in a βransomware-as-a-serviceβ (RaaS) double extortion model, Europol explained. The affiliates would initially copy the data and then encrypt the files before asking for a ransom to decrypt the information and not publish it on the leak site.
The attackers exploited various vulnerabilities and used a number of methods, including single factor logins via Remote Desktop Protocol (RDP), virtual private networks (VPNs), and other remote network connection protocols as well as phishing emails with malicious attachments, the law enforcement agencies detailed.
Do you expect police authorities around the world to dismantle more ransomware networks in the near future? Tell us in the comments section below.
-
Bitcoin News - Darknet Archives
- Ukrainian Steals Bitcoin From Russian Darknet Market, Donates to Charity
Ukrainian Steals Bitcoin From Russian Darknet Market, Donates to Charity
A Ukrainian living in the U.S. has reportedly hacked a major drug market on the Russian dark web, diverting some of its crypto proceeds. The man says he donated the digital cash stolen from the illicit website to an organization delivering humanitarian aid across his war-torn homeland.
Wisconsin Resident With Ukrainian Roots Hacks Russian Dark Web Market Solaris
Ukrainian-born cyber intelligence expert Alex Holden, who left Kyiv as a teenager in the 1980s and now lives in Mequon, Wisconsin, claims he has hacked into Solaris, one of Russiaβs largest online drug markets, Forbes informs in a report.
Supported by his team at Hold Security, he was able to get hold of some of the bitcoin sent to dealers and the darknet siteβs owners. The cryptocurrency, worth over $25,000, was later transferred to Enjoying Life, a charitable foundation based in the Ukrainian capital.
Without revealing exactly how he did it, Holden explained he took control of much of the internet infrastructure behind Solaris, including some administrator accounts, obtained the websiteβs source code and a database of its users and drop off locations for drug deliveries.
For a while, the Ukrainian and his colleagues also gained access to the βmaster walletβ of the marketplace. It was used by buyers and dealers to deposit and withdraw funds and operated as the platformβs crypto exchange, the article details.
Given the rapid turnover, the wallet rarely had more than 3 BTC at a time. Holden managed to appropriate 1.6 BTC and send it to Enjoying Life. Hold Security donated another $8,000 to the charity, which provides assistance to people affected by the war in Ukraine.
Solaris Linked to βPatrioticβ Russian Hacking Collective Killnet
The darknet market Solaris is suspected of having connections to the hacking crew Killnet, which after Moscow launched its invasion in late February became one of Russiaβs βpatrioticβ hacker groups vowing to target Ukrainians and their supporters.
Killnet has also conducted a number of attacks in the U.S., including on airport and state government websites as well as the National Geospatial-Intelligence Agency. It reportedly hit the Eurovision song contest, the Estonian government and Italyβs National Health Institute.
The group was also blamed for attacking Rutor, the main rival of Solaris, which became Russiaβs leading underground drugs market after Hydra was shut down this past spring. According to U.S. cybersecurity firm Zerofox, Solaris was paying Killnet for DDoS services.
Besides the battlefield, Russia and Ukraine have also clashed in the online space, with the government in Kyiv recruiting experts for its own cyberforce. The special unit was tasked to identify and prevent Russian attacks but also hack back.
Hits such as those on Russiaβs largest bank, Sber, and the Moscow Stock Exchange have been attributed to the Ukrainian IT army. Social media accounts associated with the hacktivist collective Anonymous took responsibility for many other attacks.
What do you think about Alex Holdenβs attack on the Russian darknet market Solaris? Let us know in the comments section below.
Germany Shuts Down Hydra Market, Seizes Servers and Bitcoin
Law enforcement agencies in Germany have targeted Hydra, a leading darknet market (DNM). As part of an operation conducted with U.S. support, the German police were able to establish control over the servers of the Russian-language platform in the country and take down its website.
Investigators Hit Hydra in Germany, Confiscate Millions in Crypto
Hydra Market, one of the largest marketplaces on the darknet, has been shut down by German authorities which seized its server infrastructure. According to an announcement by the Federal Criminal Police Office (BKA), law enforcement agents also confiscated bitcoin worth around β¬23 million ($25 million). The following message appeared on Hydraβs website on Tuesday:
BKA carried out the raid together with the Central Office for Combating Cybercrime (ZIT) at the Public Prosecutorβs Office in Frankfurt which is leading the investigation against Hydraβs operators and administrators. They are wanted for running illegal online platforms facilitating the trade of drugs and money laundering.
The German police noted that Hydra had been active since at least 2015 before the seizures which came after extensive investigations by the BKA and ZIT. They started in August last year and were conducted with the participation of several U.S. agencies.
The darknet marketplace, which was accessible via the Tor network, was targeting Russian speakers. It had around 17 million customers and over 19,000 registered sellers, the press release detailed. Besides banned substances, these also offered stolen data, forged documents and digital services.
Hydra became a major darknet market after overtaking another Russian platform, DNM Ramp. According to the data compiled by the blockchain forensics company Chainalysis, the region of Eastern Europe sends more digital currency to darknet marketplaces than any other region.
Washington has been alleging Moscowβs involvement with malicious cyber actors like DNMs, ransomware groups and other crypto-related crime. In September, the U.S. Department of the Treasuryβs Office of Foreign Assets Control (OFAC) sanctioned the Russia-based crypto broker Suex which is believed to have received more than $20 million from darknet markets like Hydra.
The Treasury Department has imposed sanctions against Hydra and a crypto exchange called Garantex. The trading platform, which has been operating mostly out of Russia, is suspected of processing over $100 million in transactions linked to illicit actors and darknet markets, including $2.6 million from Hydra.
Meanwhile, the U.S. Department of Justice announced criminal charges against a Russian resident, Dmitry Pavlov, for conspiracy to distribute narcotics and conspiracy to commit money laundering. The 30-year-old Pavlov is allegedly the administrator of Hydra Marketβs servers.
German law enforcement officials think that Hydra was likely the darknet market with the highest turnover globally. BKA and ZIT have estimated that its sales reached at least β¬1.23 billion in 2020 alone. They also noted that the investigations were hampered by the platformβs own βBitcoin Bank Mixerβ service.
Do you think other darknet markets will be targeted after Hydra? Let us know in the comments section below.