US infiltrates big ransomware gang: ‘We hacked the hackers’

US Attorney General Merrick Garland, with FBI Director Christopher Wray (R) and Deputy Attorney General Lisa Monaco (L), announces the shutting down of the Hive ransomware operation on January 26, 2023. (AFP)
Short Url
Updated 27 January 2023
Follow

US infiltrates big ransomware gang: ‘We hacked the hackers’

  • Gang identified as Hive among the world’s top five ransomware networks and has heavily targeted health care
  • Hive, working with German and other partners, was estimated to have victimized some 1,300 companies globally

WASHINGTON: The FBI and international partners have at least temporarily disrupted the network of a prolific ransomware gang they infiltrated last year, saving victims including hospitals and school districts a potential $130 million in ransom payments, Attorney General Merrick Garland and other US officials announced Thursday.
“Simply put, using lawful means we hacked the hackers,” Deputy Attorney General Lisa Monaco said at a news conference.
Officials said the targeted syndicate, known as Hive, is among the world’s top five ransomware networks and has heavily targeted health care. The FBI quietly accessed its control panel in July and was able to obtain software keys it used with German and other partners to decrypt networks of some 1,300 victims globally, said FBI Director Christopher Wray.
How the takedown will affect Hive’s long-term operations is unclear. Officials announced no arrests but said, to pursue prosecutions, they were building a map of the administrators who manage the software and the affiliates who infect targets and negotiate with victims.
“I think anyone involved with Hive should be concerned because this investigation is ongoing,” Wray said.
On Wednesday night, FBI agents seized computer servers in Los Angeles used to support the network. Two Hive dark web sites were seized: one used for leaking data of non-paying victims, the other for negotiating extortion payments.
“Cybercrime is a constantly evolving threat, but as I have said before, the Justice Department will spare no resource to bring to justice anyone anywhere that targets the United States with a ransomware attack,” Garland said.

 

He said the infiltration, led by the FBI’s Tampa office, allowed agents in one instance to disrupt a Hive attack against a Texas school district, stopping it from making a $5 million payment.
It’s a big win for the Justice Department. Ransomware is the world’s biggest cybercrime headache with everything from Britain’s postal service and Ireland’s national health network to Costa Rica’s government crippled by Russian-speaking syndicates that enjoy Kremlin protection.
The criminals lock up, or encrypt, victims’ networks, steal sensitive data and demand large sums. Their extortion has evolve to where data is pilfered before ransomware is activated, then effectively held hostage. Pay up in cryptocurrency or it is released publicly.
As an example of a Hive sting, Garland said it kept one Midwestern hospital in 2021 from accepting new patients at the height of the COVID-19 epidemic.
The online takedown notice, alternating in English and Russian, mentions Europol and German law enforcement partners. The German news agency dpa quoted prosecutors in Stuttgart as saying cyber specialists in the southwestern town of Esslingen were decisive in penetrating Hive’s criminal IT infrastructure after a local company was victimized.
In a statement, Europol said companies in more than 80 countries, including oil multinationals, have been compromised by Hive and that law enforcement from 13 countries was in on the infiltration.
A US government advisory last year said Hive ransomware actors victimized over 1,300 companies worldwide from June 2021 through November 2022, netting about $100 million in payments. Criminals using Hive’s ransomware-as-a-service tools targeted a wide range of businesses and critical infrastructure, including government, manufacturing and especially health care.
Though the FBI offered decryption keys to some 1,300 victims globally, Wray said only about 20 percent reported potential issues to law enforcement.
“Here, fortunately, we were still able to identify and help many victims who didn’t report. But that is not always the case,” Wray said. “When victims report attacks to us, we can help them and others, too.”
Victims sometimes quietly pay ransoms without notifying authorities — even if they’ve quickly restored networks — because the data stolen from them could be extremely damaging to them if leaked online. Identity theft is among the risks.
John Hultquist, the head of threat intelligence at the cybersecurity firm Mandiant, said the Hive disruption won’t cause a major drop in overall ransomware activity but is nonetheless “a blow to a dangerous group.”
“Unfortunately, the criminal marketplace at the heart of the ransomware problem ensures a Hive competitor will be standing by to offer a similar service in their absence, but they may think twice before allowing their ransomware to be used to target hospitals,” Hultquist said.
But analyst Brett Callow with the cybersecurity firm Emsisoft said the operation is apt to lessen ransomware crooks’ confidence in what has been a very high reward-low risk business. “The information collected may point to affiliates, launderers and others involved in the ransomware supply chain.”
Allan Liska, an analyst with Recorded Future, another cybersecurity outfit, predicted indictments, if not actual arrests, in the next few months.
There are few positive indicators in the global fight against ransomware, but here’s one: An analysis of cryptocurrency transactions by the firm Chainalysis found ransomware extortion payments were down last year. It tracked payments of at least $456.8 million, down from $765.6 million in 2021. While Chainalysis said the true totals are certainly much higher, payments were clearly down. That suggests more victims are refusing to pay.
The Biden administration got serious about ransomware at its highest levels two years ago after a series of high-profile attacks threatened critical infrastructure and global industry. In May 2021, for instance, hackers targeted the nation’s largest fuel pipeline, causing the operators to briefly shut it down and make a multimillion-dollar ransom payment, which the US government later largely recovered.
A global task force involving 37 nations began work this week. It is led by Australia, which has been particularly hard-hit by ransomware, including a major medical insurer and telecom. Conventional law enforcement measures such as arrests and prosecutions have done little to frustrate the criminals. Australia’s interior minister, Clare O’Neil, said in November that her government was going on the offense, using cyber-intelligence and police agents to ” find these people, hunt them down and debilitate them before they can attack our country.”
The FBI has obtained access to decryption keys before. It did so in the case of a major 2021 ransomware attack on Kaseya, a company whose software runs hundreds of websites. It took some heat, however, for waiting several weeks to help victims unlock afflicted networks.


China, Cambodia sign major canal deal

Updated 8 sec ago
Follow

China, Cambodia sign major canal deal

  • The canal project, which was previously estimated to cost $1.7 billion — nearly 4 percent of the country’s annual gross domestic product — and stretching 180 km, is now valued at $1.16 billion with a length of 151.6 km, the Cambodian government said in a

BEIJING:  China and Cambodia have agreed to build safe and stable supply chains and strengthen cooperation in transportation infrastructure, they said in a joint statement released by China’s Foreign Ministry on Friday.
The two countries also signed a deal to construct a major canal, which Cambodia hopes will transform its economic fortunes.
The agreements came after Chinese President Xi Jinping’s three-nation tour of Southeast Asia, which included stops in Vietnam and Malaysia.
The trip was part of Beijing’s effort to consolidate economic and trading ties with close neighbors.
“China supports Cambodia in building the Funan Techo Integrated Water Conservancy Project in accordance with the principles of feasibility and sustainability,” the joint statement said.
The canal project, which was previously estimated to cost $1.7 billion — nearly 4 percent of the country’s annual gross domestic product — and stretching 180 km, is now valued at $1.16 billion with a length of 151.6 km, the Cambodian government said in a separate statement.
The statement showed that it will be financed through a public-private partnership, with Cambodian investors holding a 51 percent stake and Chinese investors holding 49 percent.
China also commended Cambodia’s efforts in cracking down on illegal online gambling and telecom fraud in the joint statement, with the two countries agreeing to strengthen law enforcement cooperation further.
Before Xi’s visit, the Cambodian government said it had deported to China several “Chinese criminals,” including people from Taiwan, in a move that angered Taipei and was praised by Beijing.
The two countries also agreed to establish a ministerial dialogue between their foreign and defense ministers to facilitate coordination on major strategic issues.

 


Three tourists among 4 killed after Italian cable car crashes into a ravine south of Naples

Updated 18 April 2025
Follow

Three tourists among 4 killed after Italian cable car crashes into a ravine south of Naples

  • An Arab woman with Israeli citizenship was the third foreign victim to be identified following Thursday’s accident
  • The fourth victim was the Italian driver of the cable car

ROME: Three tourists, including a brother and sister from Britain, were among four people who were killed when a mountain cable car plunged into a ravine south of Naples, an Italian official said Friday.
An Arab woman with Israeli citizenship was the third foreign victim to be identified following Thursday’s accident, said Marco De Rosa, a spokesperson for the mayor of Vico Equense.
The fourth victim was the Italian driver of the cable car. A fifth tourist, said to be the brother of the Israeli victim, is in a stable but critical condition at a Naples hospital, officials said.
Initial reports suggested that a traction cable may have snapped as the cable car ascended Monte Faito, in the town of Castellammare di Stabia. The cable car plunged into a ravine after stopping very close to the station at the top of the peak, at around 1,050 meters (3,400 feet).
Sixteen passengers were helped out of another cable car that was stuck mid-air near the foot of the mountain following the incident.
The accident happened just a week after the cable car, which is popular for its views of Mount Vesuvius and the Bay of Naples, reopened for the season. It averages around 110,000 visitors each year.
The emergency services, including Italy’s alpine rescue, more than 50 firefighters, police and civil protection personnel, worked into the evening in severe weather conditions, with fog and strong winds making rescue operations difficult.
“The traction cable broke. The emergency brake downstream worked, but evidently not the one on the cabin that was entering the station,” Luigi Vicinanza, the mayor of Castellammare di Stabia, said on Thursday. He added that there had been regular safety checks on the cable car line, which runs 3 kilometers (1.8 miles) from the town to the top of the mountain.
Local prosecutors have opened an investigation into possible manslaughter, which will involve an inspection of the cable stations, the pylons, the two cabins and the cable, officials said Friday.
The company running the service, the EAV public transport firm, said the seasonal cable car had reopened with all the required safety conditions.
“The reopening had taken place a week ago after three months of tests every day, day and night,” said EAV President Umberto De Gregorio. “This is something inexplicable.”
De Gregorio said technical experts believed there was no connection between the severe weather and the cause of the crash. “There is an automatic system. When the wind exceeds a certain level, the cable car stops automatically,” he said.
The Monte Faito cable car opened in 1952. Four people died in 1960 when a pylon broke.
Italy has recorded two similar fatal accidents involving cable cars in recent years.
A cable car crash in May 2021 in northern Italy killed 14 people, including six Israelis, among them a family of four. In 1998, a low-flying US military jet cut through the cable of a ski lift in Cavalese, in the Dolomites, killing 20 people.


Half a million weapons lost or smuggled after Taliban takeover in Afghanistan

Updated 18 April 2025
Follow

Half a million weapons lost or smuggled after Taliban takeover in Afghanistan

  • When Taliban swept through Afghanistan, they captured about 1 million pieces of US-funded military equipment
  • Many weapons were abandoned by retreating Afghan soldiers or left behind by US forces

LONDON: Around half a million weapons seized by the Taliban after their 2021 takeover of Afghanistan have been lost, sold, or smuggled to militant groups, according to sources who spoke to the BBC.

Some of the missing weapons are believed to be in the hands of Al-Qaeda affiliates, UN officials say.

When the Taliban swept through Afghanistan, they captured about 1 million pieces of US-funded military equipment, including M4 and M16 rifles, according to the report published on Thursday.

Many weapons were abandoned by retreating Afghan soldiers or left behind by US forces, it added.

At a closed-door UN meeting in Doha last year, Taliban officials reportedly admitted that half of this equipment is now “unaccounted for.”

A UN report in February said groups such as Tehreek-e-Taliban Pakistan and the Islamic Movement of Uzbekistan were accessing Taliban-captured weapons or buying them on the black market.

The Taliban government denies the claims, insisting that all weapons are securely stored.

However, a 2023 UN report said local Taliban commanders were allowed to keep 20 percent of seized US arms, fueling a thriving black market.

Sources described an underground trade where US-made weapons are now sold via messaging apps like WhatsApp.

Oversight of US equipment in Afghanistan has long been criticized, and a US watchdog, Sigar, said tracking efforts were hampered by poor record-keeping across multiple agencies.

US President Donald Trump has vowed to reclaim the lost weaponry, though experts argue the cost of recovery would outweigh its value.

Meanwhile, the Taliban have used captured Humvees, rifles, and other simpler equipment to bolster their military strength, although they struggle to maintain more complex machinery like Black Hawk helicopters.

Concerns remain that the flow of advanced weaponry to militant groups will continue to destabilize the region.


Australian to stand trial in Russian-occupied Ukraine on mercenary charges

Updated 18 April 2025
Follow

Australian to stand trial in Russian-occupied Ukraine on mercenary charges

  • Jenkins came to Ukraine in February 2024 from Melbourne
  • Then fought against the Russian army between March and December 2024

MOSCOW: An Australian man will stand trial on mercenary charges in Russian-occupied Lugansk, the eastern region’s Moscow-installed authorities said on Friday, the latest foreign soldier fighting for Ukraine to appear before the court.
“The Prosecutor’s Office of the Lugansk People’s Republic approved the indictment in the criminal case against 33-year-old citizen of the Commonwealth of Australia Oscar Charles Augustus Jenkins,” the authorities said in a statement.
According to the investigators, Jenkins came to Ukraine in February 2024 from Melbourne and then fought against the Russian army between March and December 2024, for which he was paid around $7,000-9,000 a month.
Russia and its eastern Ukraine proxies typically consider foreigners traveling to fight in Ukraine as “mercenaries.”
This enables them to prosecute fighters under its criminal code, rather than treating them as captured prisoners of war with protections and rights under the Geneva Convention.
Most recently British man James Scott Rhys Anderson, 22, was charged with terrorism after he was caught in the Kursk region fighting on Ukraine’s side.


Prince Harry requested taxpayer-funded security after Al-Qaeda death threat

Updated 18 April 2025
Follow

Prince Harry requested taxpayer-funded security after Al-Qaeda death threat

  • The prince is in a legal battle with the Home Office over the level of protection he receives in Britain
  • Terror group called for prince ‘to be murdered’ after 2020 decision to reduce his security, court told

LONDON: The UK’s Prince Harry, duke of Sussex, requested taxpayer-funded protection following a murder threat against him by Al-Qaeda, new court documents show.

The prince is in a legal battle with the UK Home Office over the level of taxpayer-funded personal security he receives when traveling back home from the US, and the documents were revealed following the duke of Sussex’s appearance at London’s Royal Courts of Justice last week, The Independent newspaper reported.

The Executive Committee for the Protection of Royalty and Public Figures (RAVEC) ordered in 2020 that Prince Harry should receive a lower grade of security when in the UK.

He fought back against the decision, but the High Court dismissed his case against the Home Office last year, which he is now appealing.

Private evidence was heard in the case, showing that Prince Harry submitted a request for protection following the Al-Qaeda threat.

A court summary said the prince “confirmed that he had requested certain protection after a threat was made against him” by the terror organization.

Prince Harry previously claimed he faces a greater risk than Princess Diana, his late mother, with “additional layers of racism and extremism.”

After the RAVEC decision in 2020, Al-Qaeda called for Prince Harry “to be murdered,” written submissions in the prince’s appeal say.

Shaheed Fatima KC, for the prince, said that his security team was told that Al-Qaeda had released a document which said his “assassination would please the Muslim community.”

The RAVEC decision was made after Prince Harry and Meghan Markle announced they would step back from public duties in early 2020.

The pair were later told that, while in the UK, they would no longer receive the full-scale police protection offered to the king and queen, the prince and princess of Wales, and their three children.

An alternative “bespoke” security detail was arranged for the duke and duchess of Sussex.

They are required to give 30 days’ notice of their arrival in Britain for officials to make threat assessments.

Prince Harry had been “singled out for different, unjustified and inferior treatment,” Fatima said, adding that he “does not accept that ‘bespoke’ means ‘better.’”