❌

Reading view

There are new articles available, click to refresh the page.

Hive Ransomware Network Dismantled by American, European Law Enforcement

Hive Ransomware Network Dismantled by American, European Law Enforcement

Law enforcement authorities from over a dozen countries in Europe and North America have taken part in disrupting the activities of the Hive ransomware group, the U.S. Justice Department and Europol announced. Hive is believed to have targeted various organizations worldwide in the past couple of years, often extorting payments in cryptocurrency.

Captured Decryption Keys Helped Hive Victims Avoid Paying $130 Million in Ransom

Ransomware network Hive, which has had around 1,500 victims in more than 80 countries, has been hit in a months-long disruption campaign, the U.S. Department of Justice (DOJ) and the European Union Agency for Law Enforcement Cooperation (Europol) revealed. A total of 13 nations participated in the operation, including EU member states, the U.K. and Canada.

Hive has been identified as a major cybersecurity threat as the ransomware has been used by affiliated actors to compromise and encrypt data and computer systems of government facilities, oil multinationals, IT and telecom companies in the EU and U.S., Europol said. Hospitals, schools, financial firms, and critical infrastructure have been targeted, the DOJ noted.

It has been one of the most prolific ransomware strains, Chainalysis pointed out, which has collected at least $100 million from victims since its launch in 2021. A recent report by the blockchain forensics company unveiled that revenue from such attacks has decreased last year, with a growing number of affected organizations refusing to pay the demanded ransoms.

According to the announcements by the law enforcement authorities, the U.S. Federal Bureau of Investigation (FBI) penetrated Hive’s computers in July 2022 and captured its decryption keys, providing them to victims around the world which prevented them from paying another $130 million.

Working with the German Federal Police and the Dutch High Tech Crime Unit, the Bureau has now seized control over the servers and websites that Hive used to communicate with its members and the victims, including the darknet domain where the stolen data was sometimes posted. FBI Director Christopher Wray was quoted as stating:

The coordinated disruption of Hive’s computer networks … shows what we can accomplish by combining a relentless search for useful technical information to share with victims.

The Hive ransomware was created, maintained and updated by developers while being employed by affiliates in a β€˜ransomware-as-a-service’ (RaaS) double extortion model, Europol explained. The affiliates would initially copy the data and then encrypt the files before asking for a ransom to decrypt the information and not publish it on the leak site.

The attackers exploited various vulnerabilities and used a number of methods, including single factor logins via Remote Desktop Protocol (RDP), virtual private networks (VPNs), and other remote network connection protocols as well as phishing emails with malicious attachments, the law enforcement agencies detailed.

Do you expect police authorities around the world to dismantle more ransomware networks in the near future? Tell us in the comments section below.

OSCE Trains Uzbekistan Law Enforcement to Track and Seize Crypto, Search Dark Web

OSCE Trains Uzbekistan Law Enforcement to Track and Seize Crypto, Search Dark Web

The Organization for Security and Co-operation in Europe (OSCE) has set out to teach law enforcement officers in Uzbekistan how to conduct crypto and dark web investigations. The regional body recently organized a training course for employees of the country’s security agencies in Tashkent.

Uzbekistan Police and Security Agents Attend OSCE Course on Cryptocurrencies

Representatives of Uzbekistan’s Prosecutor General’s Office, the Ministry of Internal Affairs, and the State Security Service have taken a training course on cryptocurrency and dark web investigations held by the OSCE between Oct. 17 and 21 in the capital Tashkent.

The course was organized by the OSCE Transnational Threats Department in co-operation with the OSCE Project Co-ordinator in Uzbekistan and the Academy of the Prosecutor General’s Office, the intergovernmental security body said on its website.

β€œParticipants learned about the main concepts and key trends in the areas of internetworking, anonymity and encryption, cryptocurrencies, obfuscation techniques, dark web, and Tor networks,” the announcement detailed.

They also practiced various approaches and methods for seizure of crypto assets, blockchain analysis, and darknet searching. The course was based on materials provided by the European Cybercrime Training and Education Group (ECTEG).

A new computer classroom donated by the OSCE to the Prosecutor General’s Academy was inaugurated before the course by Deputy Prosecutor General of Uzbekistan Erkin Yuldashev and Acting OSCE Project Co-ordinator in Uzbekistan Hans-Ulrich Ihm.

Crypto Training in Region to Continue Throughout Next Year

Digital technologies have been transforming the criminal landscape, noted Evgeniy Kolenko who heads the Prosecutor General’s Academy. He insisted that educating law enforcement in this field needs a long-term and systematic approach.

β€œCybercrime education requires adequate equipment – both hardware and software,” added Gayrat Musaev, Head of the Academy’s Department for Implementation of Information and Communication Technologies and Information Security. Musaev also praised the new dark web lab.

The OSCE course is the first of this kind in Uzbekistan within the second phase of the β€œCapacity Building on Combating Cybercrime in Central Asia” project funded by the U.S., Germany, and South Korea. Similar training activities will continue across the region throughout 2022 and 2023.

This year, the government in Tashkent has been taking steps to more comprehensively regulate Uzbekistan’s crypto sector. In the spring, President Shavkat Mirziyoyev issued a decree providing definitions for terms like crypto assets and exchange. New registration rules for crypto miners were presented in June and earlier in October, Uzbekistan introduced monthly fees for crypto companies.

Do you think law enforcement authorities in Central Asia will continue to increase focus on the crypto space? Share your thoughts on the subject in the comments section below.

Russia Takes Down 4 Carding Sites With Over $260 Million in Crypto Turnover

Russia Takes Down 4 Carding Sites With Over $260 Million in Crypto Turnover

Law enforcement in Russia has blocked major sites on the dark web, including a carding market leader. The platforms have been seized amid ongoing investigations into hacking groups, with Russian authorities ramping up efforts to dismantle the cybercrime rings and detain their members.

Interior Ministry of Russia Hits Stolen Credit Cards Market

The Ministry of Internal Affairs of the Russian Federation (MVD) has brought down four prominent websites operating on the dark web, blockchain forensics firm Elliptic has revealed. The sites have been blocked by Directorate β€œK”, MVD’s unit combatting computer-related crime.

The seized platforms are the Sky-Fraud forum, Trump’s Dumps, UAS Store, and Ferum Shop, which became the leading market for stolen credit cards after the largest marketplace in the niche, Unicc, was taken offline in January, the report details.

According to Elliptic’s estimate, the sites have collectively made more than $263 million in crypto sales denominated in bitcoin (BTC), ether (ETH), and litecoin (LTC) before they were shut down. Ferum accounts for the bulk of that amount with $256 million in bitcoin generated, or 17% of the carding market.

Trump’s Dumps, another website distributing compromised card data, has allegedly made around $4.1 million since its launch in 2017. Both sites were advertised on the on Sky-Fraud forum, where carding techniques and money laundering tips were among the main topics. Directorate β€œK” has apparently left a message in its source code, reading: β€œWhich one of you is next?”

[#Russia] SKY-FRAUD & FERUM, famous Russian #carding forums closed by Russian authorities.

Authorities left an easter egg on the code source saying β€œWHICH ONE OF YOU IS NEXT?”#cybercrime #takedown #infosec #banking pic.twitter.com/RbNTkWPHIc

β€” Soufiane Tahiri (@S0ufi4n3) February 7, 2022

The fourth blocked website, UAS Store, was a platform offering stolen remote desktop protocol credentials that cybercriminals use to gain access to victims’ accounts from other devices. These breaches have increased during the Covid-19 pandemic as more employees are now working from home. Since late 2017, UAS Store has made around $3 million in cryptocurrency.

Russia Takes Down 4 Carding Sites With Over $260 Million in Crypto Turnover

Elliptic notes that the latest seizures have been executed after the previous top carding marketplace, Unicc, and its affiliate proxy market Luxsocks, became inaccessible in mid-January. The seizures also came after the subsequent arrest of Unicc’s suspected administrator by the Russian Federal Security Service (FSB). Researchers claim the crypto proceeds of the two platforms reached $372 million.

Meanwhile, the MVD has sought through a Moscow court the arrest of six unidentified hackers accused of β€œillegal circulation of means of payment.” Whether the group is linked to the closed-down dark web sites is not clear yet. Last month, FSB and MVD busted the notorious Revil ransomware group on a U.S. request, detaining 14 of its suspected members.

Do you think Russia will continue to crack down on dark web platforms and hacking groups? Tell us in the comments section below.

❌