DarkSide, blamed for colonial pipeline attack, says it’s shutting down

[ad_1]

Since opening the DarkSide account in March, Elliptic said, he had received $ 17.5 million from 21 Bitcoin wallets, indicating the number of ransoms he collected this spring. Cyber ​​security analysts believe the group has been active since at least August and has most likely used a number of different Bitcoin wallets to receive ransoms.

But on Thursday, someone withdrew around 113.5 Bitcoin, or $ 5.6 million, from DarkSides’ Bitcoin wallet and moved it to an unknown user account, according to TRM Labs, an intelligence firm on the San Francisco blockchain. The sum was Colonials 75 Bitcoin ransom plus that of a German company, Brenntag, which also chose to pay its digital extortionists, TRM Labs said.

Who owns this other account is another twist in the hack episode.

It’s hard to speculate, Esteban Castao, co-founder of TRM Labs, said in an interview on Friday. He noted that anyone who moved DarkSides earnings would have had access to the group’s private key for their Bitcoin wallet.

The question is where were these private keys stored? Mr. Castao said. Were they on a server that someone else got their hands on? Or did DarkSide initiate the transfer itself?

The scrutiny that followed the Colonial Pipeline attack clearly destabilized the ransomware groups. This week, the operators behind two major Russian-language ransomware platforms, REvil and Avaddon, announced tough new rules governing the use of their products, including bans on targeting government-affiliated entities, hospitals or educational institutions.

The administrator of XSS, a popular Russian-language cybercrime forum, announced an immediate ban on all ransomware activity on the forum, citing, among other things, the bad press associated with the industry. In a statement posted to the forum, the administrator drew attention to a critical mass of prejudice, nonsense, hype and noise, saying even Russian President Vladimir V. Putin’s spokesperson had weighed in on the attack on the colonial pipe. (Spokesman Dmitry S. Peskov denied that the Kremlin was involved in the pipeline attack.)

The word ransom has become associated with a whole host of nasty things: geopolitics, blackmail, government cyberattacks, the XSS administrator wrote. This word has become dangerous and poisonous.

[ad_2]

picture credit

Related Posts