Conversation with a top Ukrainian cyber official: What we know, what we don’t, what it means

Cybersecurity officials in Ukraine issued a warning Monday about yet another phishing attack using either compromised or spoofed government email addresses, the second such warning since Saturday. Monday’s alert warned of attackers targeting government institutions with malware-laced bait documents hosted on Discord that come to targets within emails from the National Health Service of Ukraine. The malware deploys a program called OutSteel that looks for certain file extensions and steals them, and also deploys a second malicious program called SaintBot. Monday’s bulletin comes two days after government officials there warned of compromised email accounts from the Ukrainian judiciary being used to target mostly Ukrainian government targets with malware hidden within phony court inquiries. Both operations come roughly two weeks after a cyberattack targeting Ukrainian government systems that wiped some computers and defaced the websites of dozens of agencies’ sites. All of the attacks are linked as part of “hybrid aggression, […]

The post Conversation with a top Ukrainian cyber official: What we know, what we don’t, what it means appeared first on CyberScoop.

Continue reading Conversation with a top Ukrainian cyber official: What we know, what we don’t, what it means

Top Russian official cites REvil arrests as sign of cooperation, says Moscow is awaiting reciprocation

The Russian government’s Jan. 14 takedown of suspects associated with the notorious REvil ransomware group was an example of increasing cooperation between the U.S. and Russian governments on cybersecurity matters, a top Russian official said Friday, but the Russian government is still waiting for U.S. reciprocation on its own cyber requests. In a wide-ranging interview, Dmitry Medvedev, the former president and prime minister of Russia and currently the deputy secretary of the country’s Security Council, called the REvil arrests a “joint operation” and “perhaps one of the few areas where, despite very problematic relations with the United States, our cooperation has intensified.” Nevertheless, he added, the Russian government is waiting for definitive answers on what the Russian government considers distributed denial-of-service (DDoS) attacks on components of its remote election infrastructure during the September 2021 State Duma elections. The U.S. government has rebutted any notion of outside interference in those elections. […]

The post Top Russian official cites REvil arrests as sign of cooperation, says Moscow is awaiting reciprocation appeared first on CyberScoop.

Continue reading Top Russian official cites REvil arrests as sign of cooperation, says Moscow is awaiting reciprocation

Ransomware group says it took files from French Ministry of Justice

A ransomware group claimed Thursday that it stole thousands of files from the French Ministry of Justice, threatening to post “all available data” if the ransom isn’t paid by Feb. 10. The announcement appeared on the leak site of LockBit 2.0, a known ransomware-as-a-service operation that’s been active since at least September 2019, according to cybersecurity firm Emsisoft. Neither the French Ministry of Justice or the country’s main cybersecurity agency responded to a CyberScoop request for comment about the situation. A ministry spokesperson told Politico that the agency was “aware of the alert and immediately took steps to carry out the necessary checks,” but did not elaborate. The post viewed by CyberScoop on the leak site — where victim files are publicized either to pressure payments or punish victims if ransoms aren’t paid — indicates that the group may have 9,856 files, but nothing has been posted yet. Brett Callow, […]

The post Ransomware group says it took files from French Ministry of Justice appeared first on CyberScoop.

Continue reading Ransomware group says it took files from French Ministry of Justice

Unpacking the rise of BlackCat ransomware: High victim count, high payouts, customized features

Despite being a relative newcomer, the BlackCat ransomware family is moving up the list of the most prolific operators in the space, according to a report from Palo Alto Network’s Unit 42 threat intelligence unit. The group’s latest report, published Thursday and first reported by CyberScoop, found that as of December 2021, BlackCat has the seventh-most victims among all ransomware groups Unit 42 tracks, a remarkable feat considering that BlackCat initially garnered notice in mid-November 2021. “This highlights a worrying trend that newcomers (or reformed groups) can attack many victims in a short space of time,” the researchers wrote. BlackCat is a typical ransomware group in some ways, but has novel aspects that Unit 42 analyzed. Its ransomware is written in Rust, a computer coding language growing in popularity for its web application benefits, memory management and efficiency. Rust has been used in malware in the past, but BlackCat might be the […]

The post Unpacking the rise of BlackCat ransomware: High victim count, high payouts, customized features appeared first on CyberScoop.

Continue reading Unpacking the rise of BlackCat ransomware: High victim count, high payouts, customized features

Details emerge on hack of Belarusian Railways and the group behind it

In the days after a group of Belarusian hackers announced they’d breached the network of the country’s railway system, encrypted data and demanded the expulsion of Russian troops and the release of political prisoners, a lot remains unclear. But the Belarusian Cyber Partisans, the hacktivist group behind the attacks, posted a series of screenshots to Twitter Monday afternoon showing what they say show “internal assets and docs” from the hack. The group also seemed to troll Belarusian Railways with a screenshot claiming that the agency’s employees “frequently used pirated software. Do you think it’s connected to how they got hacked?” the group asked. Screenshots taken during a #ScorchingHeat cyberattack on the #belarus railroad reveal that employees frequently used pirated software. Do you think it’s connected to how they got hacked? 🙃🙃🙃 pic.twitter.com/De2R6W4Jt3 — Belarusian Cyber-Partisans (@cpartisans) January 25, 2022 It’s unclear the the extent to which the group’s hack did any […]

The post Details emerge on hack of Belarusian Railways and the group behind it appeared first on CyberScoop.

Continue reading Details emerge on hack of Belarusian Railways and the group behind it

Belarusian hacktivist group attacks Belarusian Railways as military frictions mount

A group of Belarusian hackers claim to have encrypted the servers, databases and workstations of Belarusian Railways with the aim of slowing down Russian troop movements as tensions continue to mount toward a potential Russian invasion of Ukraine. The Belarus Cyber Partisans — a group of pro-democracy hacktivists who have been targeting the Russia-friendly Belarusian government with a series of hack-and-leak operations aimed to expose government corruption — tweeted mid-morning Monday U.S. time that they’d “encrypted some of BR’s servers, databases and workstations to disrupt operations.” They demanded the release of 50 political prisoners they say are the most in need of medical attention want Russian troops to stay out of their country. Franak Viacorka, an adviser to a Belarusian human rights advocate, tweeted screenshots purporting to show access to the railway company’s servers. Additional screenshots of the data were posted by the Cyber Partisans’ Telegram account. We have encryption […]

The post Belarusian hacktivist group attacks Belarusian Railways as military frictions mount appeared first on CyberScoop.

Continue reading Belarusian hacktivist group attacks Belarusian Railways as military frictions mount

Researchers find similarities between NotPetya, attacks on Ukrainian government websites

The malware that wiped dozens of government computer systems in Ukraine starting on Jan. 13 shares some strategic similarities to to the NotPetya wiper that was used to attack Ukraine in 2017 and ended up causing nearly $10 billion in damages worldwide, researchers said Friday. The analysis, from Cisco’s Talos threat intelligence division, says that the NotPetya episode should serve as warning that any organization with connections to Ukraine should “carefully consider how to isolate and monitor those connections to protect themselves from potential collateral damage.” The warning comes as the military buildup along the Ukraine border with Russia continues and worries that Russia is planning to invade its neighbor, a claim the Russian government denies. On Jan. 14 roughly 80 Ukrainian government agencies’ websites were defaced, garnering headlines around the world. Although that attack was relatively simple and the sites were restored in short order, malware known as WhisperGate […]

The post Researchers find similarities between NotPetya, attacks on Ukrainian government websites appeared first on CyberScoop.

Continue reading Researchers find similarities between NotPetya, attacks on Ukrainian government websites

Cyber experts question Biden’s tit-for-tat approach with Russia

President Joe Biden said this week that the U.S. government could respond to Russian cyberattacks on Ukraine “the same way, with cyber.” The answer may have been a standard U.S. government response about responding in-kind, especially in the context of a deteriorating security situation on the border between Ukraine and Russia, with Biden predicting a Russian invasion. National security experts, foreign leaders and Biden’s domestic political opponents criticized his overall remarks on the potential Western response to any Russian incursion, but the cyber-specific comments got their own round of questions from cybersecurity experts as well. To some, Biden’s words reflected dated and misguided thinking that sounds good and tough but makes no sense in the real world. “Tit-for-tat cyber has always been a fantasy for policymakers,” tweeted Jacquelyn Schneider, a Hoover Fellow at Stanford University and expert in cyber policy and national security. She pointed to the difficulty that the […]

The post Cyber experts question Biden’s tit-for-tat approach with Russia appeared first on CyberScoop.

Continue reading Cyber experts question Biden’s tit-for-tat approach with Russia

Interpol arrests 11 alleged members of Nigerian scam syndicate ‘SilverTerrier’

International law enforcement authorities say they’ve arrested nearly a dozen members of a notorious Nigerian cybercrime gang potentially responsible for targeting as many as 50,000 victims in various scams in recent years. Some of the 11 suspects are thought to be associated with “SilverTerrier,” a syndicate accused of employing a range of malware variants in tens of thousands of financial scams dating back to at least 2014, Interpol said Wednesday. The announcement comes two months after three members of the same group were arrested after a year-long Interpol-led investigation called Operation Falcon into the prolific business email compromise (BEC) scams the group’s members are alleged to have pulled off over the years. Authorities called this latest roundup Operation Falcon II. The arrests occurred between Dec. 13 and 22, but it’s not clear exactly where. A statement from a senior Nigerian law enforcement official and included in the Interpol release referenced […]

The post Interpol arrests 11 alleged members of Nigerian scam syndicate ‘SilverTerrier’ appeared first on CyberScoop.

Continue reading Interpol arrests 11 alleged members of Nigerian scam syndicate ‘SilverTerrier’

International effort takes down VPN service, VPNLab, used for criminal activity

A virtual private network service used for malware distribution, ransomware operations and other cybercrime activities was taken offline Monday as law enforcement officials from nearly a dozen countries jointly seized its website and customer data. Multiple investigations into the distribution of malware and other illicit activities alerted authorities to VPNLab.net, according to the European law enforcement agency Europol, which announced the takedown Tuesday. Authorities “seized or disrupted 15 servers” that hosted the site’s infrastructure, the agency said. “This service provided a platform for the anonymous commission of high value cybercrime cases, and was involved in several major international cyberattacks,” a message posted to the site’s home page reads. “Law enforcement has now gained access to the vpnlab.net servers and seized the customer data stored within. The investigation regarding customer data of this network will continue.” Led by German police, the operation included the Netherlands, Canada, the Czech Republic, France, Hungary, […]

The post International effort takes down VPN service, VPNLab, used for criminal activity appeared first on CyberScoop.

Continue reading International effort takes down VPN service, VPNLab, used for criminal activity