Posts

Showing posts with the label Conti

Conti's Attack Against Costa Rica Sparks a New Ransomware Era

A pair of ransomware attacks crippled parts of the country—and rewrote the rules of cybercrime. For the last two months, Costa Rica has been under siege. Two major ransomware attacks have crippled many of the country’s essential services, plunging the government into chaos as it scrambles to respond. Officials say that international trade ground to a halt as the ransomware took hold and more than 30,000 medical appointments have been rescheduled, while tax payments have also been disrupted. Millions have been lost due to the attacks, and staff at affected organizations have turned to pen and paper to get things done.

Costa Rica May Be Pawn in Conti Ransomware Group’s Bid to Rebrand, Evade Sanctions

By  Krebs On Security Costa Rica’s national health service was hacked sometime earlier this morning by a Russian ransomware group known as Hive . The intrusion comes just weeks after Costa Rican President Rodrigo Chaves declared a state of emergency in response to a data ransom attack from a different Russian ransomware gang — Conti . Ransomware experts say there is good reason to believe the same cybercriminals are behind both attacks, and that Hive has been helping Conti rebrand and evade international sanctions targeting extortion payouts to cybercriminals operating in Russia. The Costa Rican publication CRprensa.com reports that affected systems at the Costa Rican Social Security Fund (CCSS) were taken offline on the morning of May 31, but that the extent of the breach was still unclear. The CCSS is responsible for Costa Rica’s public health sector, and worker and employer contributions are mandated by law. A copy of the ransom note left behind by the intruders and subsequen...

North Korean IT Workers Are Infiltrating Tech Companies

Plus: The Conti ransomware gang shuts down, Canada bans Huawei and ZTE, and more of the week’s top security news. By Matt Burgess, Wired As Russia's full-scale war in Ukraine heads towards its hundredth day, opposition from Ukrainian forces is as strong as ever. At the same time, hacktivists all around the world continue to breach Russian institutions and publish their files and emails. This week one hacktivist collective took a different—and slightly peculiar—approach: launching a service to prank-call Russian government officials. The new website uses leaked details to put two random Russian officials on a call with each other. It obviously won't make any difference to the outcome of the war, but the group that created it hopes the tool will cause some confusion and annoy those in Moscow. New research from Google’s Threat Analysis Group has delved into the surveillance-for-hire industry and found that spyware vendors are targeting Android devices with zero-day exploits. State...
By Lawrence Abrams, Bleeping Computer Ransomware attacks continue to slow down, likely due to the invasion of Ukraine, instability in the region, and subsequent worldwide sanctions against Russia. This does not mean, though, that there has been no ransomware activity. This week's biggest news is the Conti ransomware gang beginning to shut down their operation, with internal infrastructure taken offline and team leaders/members told that the brand is ending. While the 'Conti' brand may be shut down, cybersecurity firm Advanced Intel says that the cybercrime syndicate will continue to operate, with members joining other ransomware operations or the Conti leadership taking over smaller operations. By splintering into smaller 'cells,' it is believed that Conti will be able to evade law enforcement more easily and simply switch between different ransomware operation's encryptors. While this may mean less revenue for the syndicate, it creates greater mobility for the ...

Conti Ransomware Gang Strikes Major Component Supplier For Boeing And Lockheed Martin

Image
By Nathan Wasson, Hot Hardware The beginning of the year saw a flurry of stories about security breaches as the cybercriminal gang known as LAPSUS$ stole data from an alarming number of big name companies in a short period of time. However, while LAPSUS$ is no longer in operation, after the London police arrested all seven members of the group, other cybercriminal groups are still afoot and out to steal data. One of these groups is the Russian-based Conti ransomware group. When Russia’s war on Ukraine broke out in February, the Conti ransomware gang announced that it fully supported the Russian government and would carry out counterattacks against anyone who organized cyberattacks or other offensive measures against Russia. The group specifically called out “Western warmongers” and “American cyber aggression.” Earlier this month, the US Department of State announced its offering of up to $10 million for information that helps identify or locate key members of the Conti ransomware gang....

US offers $15 million reward for info on Conti ransomware gang

Image
By Sergiu Gatlan, Bleeping Computer The US Department of State is offering up to $15 million for information that helps identify and locate leadership and co-conspirators of the infamous Conti ransomware gang. Up to $10 million of this reward are offered for info on Conti leaders' identity and location, and an additional $5 million for leading to the arrest and/or convictions of individuals who conspired or attempted to participate in Conti ransomware attacks. According to a statement issued by State Department spokesman Ned Price, Conti has hit more than 1,000 victims who paid over $150 million in ransoms until January 2022.  "The Conti ransomware group has been responsible for hundreds of ransomware incidents over the past two years," Price said Friday . "The FBI estimates that as of January 2022, there had been over 1,000 victims of attacks associated with Conti ransomware with victim payouts exceeding $150,000,000, making the Conti Ransomware variant the costlies...

Hackers Claim to Target Russian Institutions in Barrage of Cyberattacks and Leaks

Image
By Kate Conger and David E. Sanger, New York Times Hackers claim to have broken into dozens of Russian institutions over the past two months, including the Kremlin's internet censor and one of its primary intelligence services, leaking e-mails and internal documents to the public in an apparent hack-and-leak campaign that is remarkable in its scope. The hacking operation comes as the Ukrainian government appears to have begun a parallel effort to punish Russia by publishing the names of purported Russian soldiers who operated in Bucha, Ukraine, the site of a massacre of civilians, and agents of the FSB, a major Russian intelligence agency, along with identifying information like dates of birth and passport numbers. It is unclear how the Ukrainian government obtained those names or whether they were part of the hacks. Much of the data released by the hackers and the Ukrainian government is by its nature impossible to verify. As an intelligence agency, the FSB would never confirm a l...

Conti’s Ransomware Toll on the Healthcare Industry

Image
By  KrebsOnSecurity Conti — one of the most ruthless and successful Russian ransomware groups — publicly declared during the height of the COVID-19 pandemic that it would refrain from targeting healthcare providers. But new information confirms this pledge was always a lie, and that Conti has launched more than 200 attacks against hospitals and other healthcare facilities since first surfacing in 2018 under its earlier name, “ Ryuk .” On April 13, Microsoft said it executed a legal sneak attack against Zloader , a remote access trojan and malware platform that multiple ransomware groups have used to deploy their malware inside victim networks. More specifically, Microsoft obtained a court order that allowed it to seize 65 domain names that were used to maintain the Zloader botnet. Microsoft’s civil lawsuit against Zloader names seven “John Does,” essentially seeking information to identify cybercriminals who used Zloader to conduct ransomware attacks. As the company’s complaint ...