Ransomware payments demand Treasury Department sanction on Russian crypto exchange SUEX

[ad_1]

The US Treasury Department imposed the first sanctions on a crypto exchange, hitting Russia-based SUEX.io for facilitating ransomware payments.

Founded in 2018, SUEX is not a surprising choice for this action given that it has made it clear that it specializes in illicit activities. The crypto exchange only welcomed users by invitation, required encrypted communications on Telegram, and only transacted in person at its office. The action enters a new legal foundation, however, as it represents the first formal restriction on the use of a crypto exchange by US citizens.

Russian crypto exchange Shady receives first US ban

The SUEX sanction is a first salvo in the Biden administration’s planned war on ransomware, something that has become a high priority after attacks on JBS, Colonial Pipeline and others shutting down pieces of US infrastructure. for long periods.

Despite refraining from banning ransomware payments, the administration has made it clear that it wants to attack cybercriminals and their support structures through their fundraising means. One of the bravest of these clearinghouses for illicit proceeds from cyber attacks is SUEX, which was founded in the Czech Republic and headquartered in Russia. Assistant Treasury Secretary Wally Adeyemo told media that the crypto exchange has processed at least eight ransomware payments that the agency is aware of.

With the exception of sanctioned entities, the US government does not prohibit ransomware payments, but encourages victims to immediately report incidents to authorities. In some cases, including high-profile attacks such as Colonial Pipeline, federal agencies have been able to recover substantial amounts of ransomware payments by cutting off the flow of money to crypto exchanges and other financial institutions to which they go. legally have access.

SUEX is one of the bravest crypto exchanges in terms of advertising its services to the criminal world, stopping just before removing billboards expressly promoting its ransomware-friendly features. It requires users to personally visit an office in Moscow to complete all transactions, it is not accessible without invitation, and all communications regarding money movements must be made using the messaging app. encrypted Telegram. Cryptocurrency research firm Chainalysis reports that the fragmentary cryptocurrency exchange has displaced hundreds of millions of dollars in illicit transactions since 2018, including $ 160 million in Bitcoin. At least $ 13 million appears to come from notorious Ryuk and Maze ransomware organizations. The US Treasury said at least 40% of SUEX’s transactions came from illegal activity.

SUEX is now on the Treasury’s Specially Designated Nationals and Stranded People list, which means Americans can be fined for doing business with it. President Joe Biden’s recent remarks to the United Nations General Assembly included a claim that the United States intends to establish “clear rules of the road for all nations” in cyberspace and that it will stand by. reserve the right to “respond decisively” to cyber attacks.

John Hammond, senior security researcher at Huntress, believes it will take some time to determine whether this aggressive new approach: “This Treasury effort is a step forward. At this time, we can’t say for sure if this is a step in the right direction, but it is better than none at all. It is too early to say how or even if this will impact cybercrime, but something must be done. Without this effort, or without any effort, the cryptocurrency markets will continue to be used and abused by criminals as if it was open season. “

Ransomware payments passing through targeted foreign facilitators

A small but active set of crypto exchanges, SUEX included, provide outlets for ransomware payments to be converted into hard cash by the author. These illicit banking operations know their customers, setting the conditions and costs accordingly; SUEX apparently would not process transactions under $ 10,000.

These criminal-friendly virtual crypto exchanges also take care to protect their customers from prying eyes. These are basically shop sellers connecting to larger international crypto exchanges, putting a layer of obfuscation between the customer and more legitimate outfits. SUEX also has a large amount of cash, with which it can presumably facilitate quick withdrawals for the customer while negotiating the safe laundering of ransomware payments. It’s unclear where the money comes from, but SUEX’s stakeholders include very wealthy people with ties to MTS (Russia’s largest telecommunications company) and Czech venture capital circles.

Chainalysis CTO Gurvais Grigg believes this group of criminal crypto exchanges to be very small; analysis indicates that only five like SUEX were responsible for processing 82% of ransomware payments in 2020. Additional pressure from the U.S. government is unlikely to end these processors, but Grigg believes it will force changes in the process. criminal underworld: primarily, speeding up the shift from Bitcoin to Monero as the preferred way to receive ransomware payments.

Sketchy #crypto exchange has moved hundreds of millions of dollars in illicit transactions since 2018, including $ 160 million in Bitcoin. At least $ 13 million seems to come from the famous #ransomware Ryuk and Maze. #cybersecurity #respectdataClick to Tweet

The Treasury’s Office of Foreign Assets Control (OFAC) has announced that further sanctions of this nature can be expected. While this aggressive approach may appear to be a necessary measure in the face of a problem that is spiraling out of control, James McQuiggan (Security Awareness Advocate for KnowBe4) points out that a campaign of sanctions and similar measures could end up hurting victims as well. : “The US government is using sanctions as the primary means of slowing down cryptocurrency trading. At the same time, those affected by ransomware attacks could be the most affected by these sanctions… Suppose they cannot use crypto exchanges to pay the ransom according to their policies and procedures. In this case, these sanctions remove the possibility of collecting decryption keys and prevent cybercriminals from exposing their data online … Although sanctions are a way to restrict payments, organizations must examine their environment and investigate the root cause. ransomware attacks and determine a method to prevent cybercriminals from entering through phishing or social engineering attacks.

Sources

1/ https://Google.com/

2/ https://www.cpomagazine.com/cyber-security/ransomware-payments-prompt-treasury-department-sanction-on-russian-crypto-exchange-suex/

The mention sources can contact us to remove/changing this article

[ad_2]

Related Posts