Wednesday, June 7, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Cybersecurity

FBI takes down Hive ransomware group

Researcher by Researcher
January 29, 2023
in Cybersecurity
0
FBI takes down Hive ransomware group
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Working with international law enforcement, the FBI said it has seized control of the servers the Hive group uses to communicate with members.

fbi.jpg
Image: iStockphoto/domoyega

The FBI has revealed the results of a month-long campaign designed to thwart an infamous ransomware group known for extorting hospitals, school districts and critical infrastructure. On Thursday, the agency announced that it had worked with law enforcement agencies in Germany and the Netherlands to take control of the servers used by the Hive criminal gang to communicate with its members, thus cutting off its ability to extort its victims.

The group’s dark web site now displays a message in both English and Russian stating: “This hidden site has been seized. The Federal Bureau of Investigation seized this site as part of a coordinated law enforcement action taken against Hive Ransomware.”

Related articles

Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023

SEE: Ransomware attacks are decreasing, but companies remain vulnerable (TechRepublic)

Another message indicates that this action was taken by the United States Attorney’s Office for the Middle District of Florida and the Computer Crime and Intellectual Property Section of the Department of Justice with substantial assistance from Europol.

Jump to:

Takedown of Hive’s website is the latest step

The takedown of the Hive website is just the latest in a series of steps aimed at disrupting the group’s capabilities. The FBI said that since late July of 2022, it has penetrated the gang’s computer networks, captured its decryption keys and provided those keys to victims around the world.

Offering the decryption keys to Hive victims is a crucial action, as it has saved them from collectively paying a ransom amount of $130 million. Since the FBI’s campaign started, more than 300 decryption keys have been given to Hive victims under attack, while more than 1,000 were provided to victims of the gang’s previous attacks.

Must-read security coverage

“Cybercriminals utilize sophisticated technologies to prey upon innocent victims worldwide,” said U.S. Attorney Roger Handberg for the Middle District of Florida. “Thanks to the exceptional investigative work and coordination by our domestic and international law enforcement partners, further extortion by Hive has been thwarted, critical business operations can resume without interruption, and millions of dollars in ransom payments were averted.”

History of Hive

Surfacing in 2021, Hive launched a series of attacks that quickly made it one of the most active and prominent ransomware groups. Employing the ransomware-as-a-service model, Hive develops the necessary ransomware tools and technologies and then recruits affiliates to carry out the actual attacks. After the ransom is received, Hive affiliates and administrators split the money 80/20, according to the FBI.

Using the RaaS model, Hive has targeted a variety of sectors, including hospitals, school districts, financial firms and critical infrastructure. Since June of 2021, the group has targeted more than 1,500 victims globally and captured more than $100 million in ransom payments.

Tactics of Hive

Hive is known for double extortion tactics in which the attackers not only decrypt the data to prevent its victims from accessing it but threaten to publicly leak the information unless the ransom is paid. The group has already published data stolen from victims on its leak website.

Hive affiliates gain access to the networks of intended victims through different methods, according to the U.S. Cybersecurity and Infrastructure Security Agency. In some cases, the attackers sneak in through single-factor account logins using Remote Desktop Protocol, virtual private networks or other remote connection protocols.

In other cases, they exploit vulnerabilities in FortiToken authentication products. And another common tactic involves sending phishing emails with malicious file attachments.

Challenges in taking down ransomware groups

Ransomware groups are difficult to fully wipe out because the members tend to resurface in other groups and capacities. But, the efforts by the FBI and other law enforcement agencies are designed to hit them on several fronts.

“While this is definitely a win, this is by no means the end of ransomware,” said Jordan LaRose, practice director for infrastructure security at security consulting firm NCC Group. “We have already seen a reemergence from REvil, and Hive will likely follow suit in some form.

SEE: The most dangerous and destructive ransomware groups of 2022 (TechRepublic)

“But, takedowns like these doubtlessly deter attackers and potential payees and increase awareness of the long-term effects of paying attackers.”

Collaboration and cooperation among different law enforcement entities around the world is key to winning the battle against ransomware attackers, LaRose added. Also of great help is the ability of security experts to provide critical threat intelligence to the FBI and other organizations.

Recommendations to combat ransomware

“For vulnerable organizations, this is why the primary focus must be getting their system back up and running after an attack,” said Caroline Seymour, vice president of product marketing for disaster recovery firm Zerto. “When a service provider is disabled and access to data is held in exchange for ransom, the best way to fight back and get up and running again is to have a recovery solution in place that protects systems from disruption and provides a path to instant recovery.”

However, many organizations turn to backups that are a day or even a week old to restore their data, Seymour added. That leads to gaps and data loss that can impact the business and add to the overall cost of recovery.

“The key is having a solution that’s always on with enough granularity to recover to a point in time precisely before the attack occurred without time gaps,” Seymour said. “The best solution will be one that uses continuous data protection and keeps valuable data protected in real time.”

Read next: Following year-end ransomware storm, leaders batten hatches for sea of troubles in 2023 (TechRepublic)



Source link

Tags: FBIGroupHiveRansomwaretakes
Share76Tweet47

Related Posts

Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
0

In Verizon’s just-released 2023 Data Breach Investigations Report, money is king, and denial of service and social engineering still hold...

CISA: North Korea-Backed Actors Using Maui Ransomware

North Korean Attackers Target Google Account Credentials

June 7, 2023
0

North Korean threat group Kimsuky has recently launched a social engineering campaign against a number of experts specializing in North...

Sentra Raises $30 Million for DSPM Technology

KeePass Update Patches Vulnerability Exposing Master Password

June 6, 2023
0

Open source password manager KeePass was updated over the weekend to patch a vulnerability allowing attackers to retrieve the cleartext...

Zero-day MOVEit Transfer vulnerability exploited in the wild

Zero-day MOVEit Transfer vulnerability exploited in the wild

June 6, 2023
0

Shodan search engine results for internet-facing MOVEit instances. Image: Shodan The Cybersecurity & Infrastructure Security Agency has issued an alert...

New DDoS Attack Vector Abuses Content Filtering Systems

UNC4857 Exploits MOVEit Transfer Flaw in Data Extortion Attacks

June 6, 2023
0

A newly discovered threat campaign has been observed exploiting the recently uncovered, critical-severity MOVEit Transfer vulnerability in order to launch...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
Apple launches Vision Pro & more new products

Apple launches Vision Pro & more new products

June 7, 2023
Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
Money20/20 Europe 2023: Day One TFT Roundup

Money20/20 Europe 2023: Day One TFT Roundup

June 7, 2023
Release date, price and more

Release date, price and more

June 7, 2023

Recent Posts

Apple launches Vision Pro & more new products

Apple launches Vision Pro & more new products

June 7, 2023
Ransomware, DDoS see major upsurge led by upstart hacker group

DDoS attacks dominate and pretexting lead to BEC growth

June 7, 2023
Money20/20 Europe 2023: Day One TFT Roundup

Money20/20 Europe 2023: Day One TFT Roundup

June 7, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches Payments platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved