Governments turn tables on ransomware gang REvil by pushing it offline

1 / 2
US officials talk about the Colonial Pipeline ransomware attack during a news conference in Washington, D.C. on June 7, 2021. (REUTERS/File Photo)
Short Url
Updated 22 October 2021
Follow

Governments turn tables on ransomware gang REvil by pushing it offline

  • Law enforcement and intelligence cyber specialists were able to hack REvil's computer network infrastructure, obtaining control of at least some of their servers
  • One person familiar with the events said that a foreign partner of the US government carried out the hacking operation that penetrated REvil's computer architecture

The ransomware group REvil was itself hacked and forced offline this week by a multi-country operation, according to three private sector cyber experts working with the United States and one former official.
Former partners and associates of the Russian-led criminal gang were responsible for a May cyberattack on the Colonial Pipeline that led to widespread gas shortages on the US East Coast. REvil's direct victims include top meatpacker JBS. The crime group's "Happy Blog” website, which had been used to leak victim data and extort companies, is no longer available.
Officials said the Colonial attack used encryption software called DarkSide, which was developed by REvil associates.
VMWare head of cybersecurity strategy Tom Kellermann said law enforcement and intelligence personnel stopped the group from victimizing additional companies.
"The FBI, in conjunction with Cyber Command, the Secret Service and like-minded countries, have truly engaged in significant disruptive actions against these groups,” said Kellermann, an adviser to the US Secret Service on cybercrime investigations. “REvil was top of the list.”
A leadership figure known as "0_neday," who had helped restart the group's operations after an earlier shutdown, said REvil's servers had been hacked by an unnamed party.
"The server was compromised, and they were looking for me," 0_neday wrote on a cybercrime forum last weekend and first spotted by security firm Recorded Future. "Good luck, everyone; I'm off."
US government attempts to stop REvil, one of the worst of dozens of ransomware gangs that work with hackers to penetrate and paralyze companies around the world, accelerated after the group compromised US software management company Kaseya in July. 
That breach opened access to hundreds of Kaseya's customers all at once, leading to numerous emergency cyber incident response calls.

Decryption key
Following the attack on Kaseya, the FBI obtained a universal decryption key that allowed those infected via Kaseya to recover their files without paying a ransom.
But law enforcement officials initially withheld the key for weeks as it quietly pursued REvil's staff, the FBI later acknowledged. 
According to three people familiar with the matter, law enforcement and intelligence cyber specialists were able to hack REvil's computer network infrastructure, obtaining control of at least some of their servers.
After websites that the hacker group used to conduct business went offline in July, the main spokesman for the group, who calls himself "Unknown," vanished from the internet.
When gang member 0_neday and others restored those websites from a backup last month, he unknowingly restarted some internal systems that were already controlled by law enforcement.
“The REvil ransomware gang restored the infrastructure from the backups under the assumption that they had not been compromised,” said Oleg Skulkin, deputy head of the forensics lab at the Russian-led security company Group-IB. “Ironically, the gang's own favorite tactic of compromising the backups was turned against them.”
Reliable backups are one of the most important defenses against ransomware attacks, but they must be kept unconnected from the main networks or they too can be encrypted by extortionists such as REvil.
A spokesperson for the White House National Security Council declined to comment on the operation specifically.
"Broadly speaking, we are undertaking a whole of government ransomware effort, including disruption of ransomware infrastructure and actors, working with the private sector to modernize our defenses, and building an international coalition to hold countries who harbor ransom actors accountable," the person said.
The FBI declined to comment.
One person familiar with the events said that a foreign partner of the US government carried out the hacking operation that penetrated REvil's computer architecture. A former US official, who spoke on condition of anonymity, said the operation is still active.
The success stems from a determination by US Deputy Attorney General Lisa Monaco that ransomware attacks on critical infrastructure should be treated as a national security issue akin to terrorism, Kellermann said.
In June, Principal Associate Deputy Attorney General John Carlin told Reuters the Justice Department was elevating investigations of ransomware attacks to a similar priority.
Such actions gave the Justice Department and other agencies a legal basis to get help from US intelligence agencies and the Department of Defense, Kellermann said.
"Before, you couldn't hack into these forums, and the military didn't want to have anything to do with it. Since then, the gloves have come off." 


Republican House bill would jack up cost of US solar home systems, PV panel makers warn

Updated 11 sec ago
Follow

Republican House bill would jack up cost of US solar home systems, PV panel makers warn

  • Proposed measure would scrap 30 percent tax credit for homeowners with solar panels
  • Bill in line with Trump move to undo Biden-era clean energy program

Companies that put solar panels on US homes say a Republican budget bill advanced in Congress this week would deal a massive blow to the industry by eliminating a generous subsidy for homeowners that had buttressed the industry’s growth.
The bill would scrap a 30 percent federal credit for taxpayers who put up rooftop systems, stifling an industry that has grown ten-fold over the last decade and which now employs more than 100,000 workers, industry players said.
“It certainly is a giant setback,” said Charlie Hadlow, president of EnergySage, an online solar marketplace. “I have solar installers in our large network passing around the contact information for bankruptcy attorneys. That’s not alarmist, that’s happening.”
Many of the biggest residential solar markets are in states that voted for President Donald Trump, including Texas, Florida and Arizona, according to the Solar Energy Industries Association trade group.
The House of Representatives Ways and Means Committee voted this week to allow the 25D tax credit to expire at the end of this year, nine years earlier than planned, as part of a Republican effort to roll back subsidies from former President Joe Biden’s signature climate law, the Inflation Reduction Act.
A spokesperson for Republicans on the committee did not immediately respond to a request for comment.
The bill still has several hurdles to clear before getting a broad package of tax cuts, spending hikes and safety-net reductions through Congress.
The White House did not immediately respond to a request for comment. Trump wants to undo federal regulations and programs introduced by Biden that are aimed at expanding clean energy and combating climate change.
More than half of residential installations qualify for the 25D tax credit, according to EnergySage, which estimates that rooftop systems will be about $8,000 or $9,000 more expensive without it.
The subsidy has been critical for small installers whose customers pay cash or take out loans and then claim the credit on their tax returns.
For panels that are owned by a third party, such as a bank, and leased to homeowners, system owners are able to claim a separate tax credit that the House bill would leave in place until 2032 but start to phase out in 2029.
That market is dominated by large players like Sunrun.
“You want to just place a larger burden on the regular Joe who pays taxes? It doesn’t seem fair,” said Jack Ramsey, CEO of Altsys Solar in Tulare, California.
Ramsey anticipates cutting his nine-person staff to four or five people if the credit is eliminated.
At the end of 2024, the US boasted 36 gigawatts of residential solar capacity, up from 3 GW in 2014 and a level equivalent to a third of the nation’s nuclear power capacity.
Rooftop solar accounts for more than a third of solar industry jobs, according to the Interstate Renewable Energy Council.
Rob Kaercher, CEO of Absolute Solar in Lansing, Michigan, has 24 employees and wants to hire more, but will not if the credit goes away.
“I strongly urge the credits to be maintained, because it would do a tremendous amount for local businesses just like ours to be able to continue to hire and grow,” Kaercher told reporters.
The move to eliminate the credit caught many in the industry off guard.
Thomas Clark, the director of marketing and communications of Northstone Solar in Whitefish, Montana, met with staff from his state’s Congressional delegation in Washington earlier this year and came away from the meeting feeling the credit was safe.
“Obviously this happening so quickly after those meetings really hurts as a constituent,” Clark said.


Macron calls for peace in first talk with new pope

Updated 38 min 2 sec ago
Follow

Macron calls for peace in first talk with new pope

PARIS: French President Emmanuel Macron said on Thursday he had called Pope Leo XIV and talked about efforts to reach peace in Ukraine and Gaza in his first conversation with the new pontiff.
In their “first exchange,” the pair “addressed the efforts to let the weapons fall silent wherever conflicts rage in the world, and in particular for a solid and lasting peace in Ukraine and Gaza,” Macron said on X.
“We share the ambition to reconcile the fight against poverty and the protection of the planet,” the French leader said, adding that he had “once again congratulated” the pontiff on his election as head of the Catholic Church last week.
While Macron is not scheduled to join the ranks of the world leaders attending Pope Leo’s inaugural mass in Rome on Sunday morning, France’s Prime Minister Francois Bayrou is due to attend.


Nigeria army head vows to counter jihadist attacks

Updated 48 min 20 sec ago
Follow

Nigeria army head vows to counter jihadist attacks

MAIDUGURI, Nigeria: Nigeria’s top military officer on Thursday told troops in a region battling increased jihadist unrest that the attacks would be quickly resolved.
The Islamic State West Africa Province group and its rival Boko Haram have intensified assaults on military bases in recent weeks, notably in the northeastern state of Borno, epicenter of an insurgency dating back to 2009.
According to an AFP tally, at least 10 bases have been attacked in two months. At least 100 people, including civilians, were killed in attacks in April.
“Actions have been taken to ensure that we address the series of attacks,” chief of defense staff General Christopher Musa told troops in Borno’s capital Maiduguri, promising new material was being drafted in.
Musa said conflict in the Sahel states including Mali, Chad and Niger “has put a lot of pressure on Nigeria and that’s why you see recent attacks have occurred.”
“Whatever is going on is just for a short while,” he said.
Musa suggested fencing Nigeria’s borders, saying “there are countries that have fenced over a 1,500 kilometer (930 mile) stretch” — roughly the length of the Nigeria-Niger frontier.
While violence has fallen from its 2014-2015 peak, the governor of Borno recently warned that the military was losing ground to jihadists, and the latest attacks have put the conflict back in the spotlight.
More than 40,000 people have been killed and two million displaced in northeast Nigeria since 2009, according to the United Nations.
A Multinational Joint Task Force, a coalition created by Nigeria, Niger, Cameroon, Benin and Chad to fight cross-border armed groups, has been hampered by the withdrawal of Niger and threats by Chad to do the same.
According to a recent Nigerian intelligence report seen by AFP, there are also internal problems.
Late payment of salaries “has been a recurring problem,” particularly in the northeast, it said.
The report warned of “frustration and demotivation among security personnel, which could potentially lead to mutinies or unrest, if not urgently addressed.”
President Bola Tinubu this week called for the creation of a “forest guards” unit “to flush out terrorists and criminal gangs.”
Nigeria’s vast, often inaccessible forests have become havens for jihadist and armed criminal groups.
While the Nigerian army often works with local self-defense groups, questions remain over how the proposed forest guard be financed, work with existing security forces and even how long it would take to set up.


13 hurt when car plows into crowd before Spanish footbal match

Updated 48 min 31 sec ago
Follow

13 hurt when car plows into crowd before Spanish footbal match

  • Police ruled case as an accident, described all injuries as "minor"
  • Driver arrested on suspicion of dangerous driving and causing injury

BARCELONA: At least 13 people were hurt when a driver lost control and plowed into a crowd gathered outside a football match between RCD Espanyol and city rivals FC Barcelona, police said on Thursday.
Police said people were hurt when the vehicle rammed into the crowd outside RCD Españyol soccer stadium in Barcelona at the start of the game.
Police added in a statement on social media site X that the incident did not present any danger to the crowd inside the stadium.
Salvador Illa, the Catalan regional president, said on Thursday all the injuries were “minor” and ruled out any deliberate attack.
The driver has been arrested on suspicion of dangerous driving and causing injury.


New Royal Navy chief under renewed scrutiny over Afghanistan war crimes evidence

Updated 15 May 2025
Follow

New Royal Navy chief under renewed scrutiny over Afghanistan war crimes evidence

  • Gen. Gwyn Jenkins previously accused of failing to report evidence of war crimes committed by British forces
  • It is also alleged he oversaw rejection of hundreds of resettlement applications from Afghans who served alongside British troops against the Taliban

LONDON: The man chosen as the new head of the UK’s Royal Navy was previously accused of failing to report evidence of war crimes allegedly committed by British forces in Afghanistan.

Gen. Sir Gwyn Jenkins, who was appointed on Thursday, also faced allegations this week that he oversaw the rejection of hundreds of resettlement applications from former Afghan special forces members who served alongside British troops against the Taliban, The Guardian newspaper reported.

Jenkins replaces Adm. Ben Key, who stepped down last week over allegations of misconduct.

The new navy chief previously led UK Special Forces in Afghanistan during the war against the Taliban. That conflict is under renewed scrutiny in Britain following recent fresh allegations of war crimes involving members of Britain’s elite Special Air Service and Special Boat Service.

In 2023, it emerged that Jenkins had been warned in writing in 2011 that SAS troops had claimed to have executed handcuffed detainees in Afghanistan. Rather than refer this evidence to the Royal Military Police, the BBC reported at the time, Jenkins placed the documents in a safe. However, The Telegraph newspaper reported that Jenkins did pass the evidence up the chain of command at the time.

This week, an investigation by the BBC current affairs program “Panorama” revealed that Jenkins personally appointed an officer under his command to assess the Afghan resettlement applications. Thousands of former elite Afghan soldiers were rejected, despite credible evidence of their service alongside British counterparts.

The UK’s Ministry of Defence said it was “not appropriate … to comment on allegations which may be within the scope of the statutory inquiry,” referring to a public inquiry underway in the UK to investigate the war crimes allegations.

There was “no evidence” that Afghan resettlement applications were rejected to prevent the former soldiers from giving evidence to the war crimes inquiry, it added.

Defence Secretary John Healey on Thursday described Jenkins as a “proven leader with a distinguished career in both the military and at the core of government.”

He added: “I know he will deliver in this pivotal role, making Britain secure at home and strong abroad.”

Sarah Atherton, a former Tory MP who sat on the Defence Select Committee, told The Telegraph: “Military personnel, especially senior leaders, are held to high ethical and behavior standards.

“If somebody is facing an allegation … I know it’s alleged, but it’s just very strange to appoint someone who is in this position, given the circumstances. That is bizarre.”

Jenkins said after his appointment that he wanted to “accelerate” the Royal Navy’s return to a “war fighting force that is ready for conflict.”