US infiltrates big ransomware gang: ‘We hacked the hackers’

US Attorney General Merrick Garland, with FBI Director Christopher Wray (R) and Deputy Attorney General Lisa Monaco (L), announces the shutting down of the Hive ransomware operation on January 26, 2023. (AFP)
Short Url
Updated 27 January 2023
Follow

US infiltrates big ransomware gang: ‘We hacked the hackers’

  • Gang identified as Hive among the world’s top five ransomware networks and has heavily targeted health care
  • Hive, working with German and other partners, was estimated to have victimized some 1,300 companies globally

WASHINGTON: The FBI and international partners have at least temporarily disrupted the network of a prolific ransomware gang they infiltrated last year, saving victims including hospitals and school districts a potential $130 million in ransom payments, Attorney General Merrick Garland and other US officials announced Thursday.
“Simply put, using lawful means we hacked the hackers,” Deputy Attorney General Lisa Monaco said at a news conference.
Officials said the targeted syndicate, known as Hive, is among the world’s top five ransomware networks and has heavily targeted health care. The FBI quietly accessed its control panel in July and was able to obtain software keys it used with German and other partners to decrypt networks of some 1,300 victims globally, said FBI Director Christopher Wray.
How the takedown will affect Hive’s long-term operations is unclear. Officials announced no arrests but said, to pursue prosecutions, they were building a map of the administrators who manage the software and the affiliates who infect targets and negotiate with victims.
“I think anyone involved with Hive should be concerned because this investigation is ongoing,” Wray said.
On Wednesday night, FBI agents seized computer servers in Los Angeles used to support the network. Two Hive dark web sites were seized: one used for leaking data of non-paying victims, the other for negotiating extortion payments.
“Cybercrime is a constantly evolving threat, but as I have said before, the Justice Department will spare no resource to bring to justice anyone anywhere that targets the United States with a ransomware attack,” Garland said.

 

He said the infiltration, led by the FBI’s Tampa office, allowed agents in one instance to disrupt a Hive attack against a Texas school district, stopping it from making a $5 million payment.
It’s a big win for the Justice Department. Ransomware is the world’s biggest cybercrime headache with everything from Britain’s postal service and Ireland’s national health network to Costa Rica’s government crippled by Russian-speaking syndicates that enjoy Kremlin protection.
The criminals lock up, or encrypt, victims’ networks, steal sensitive data and demand large sums. Their extortion has evolve to where data is pilfered before ransomware is activated, then effectively held hostage. Pay up in cryptocurrency or it is released publicly.
As an example of a Hive sting, Garland said it kept one Midwestern hospital in 2021 from accepting new patients at the height of the COVID-19 epidemic.
The online takedown notice, alternating in English and Russian, mentions Europol and German law enforcement partners. The German news agency dpa quoted prosecutors in Stuttgart as saying cyber specialists in the southwestern town of Esslingen were decisive in penetrating Hive’s criminal IT infrastructure after a local company was victimized.
In a statement, Europol said companies in more than 80 countries, including oil multinationals, have been compromised by Hive and that law enforcement from 13 countries was in on the infiltration.
A US government advisory last year said Hive ransomware actors victimized over 1,300 companies worldwide from June 2021 through November 2022, netting about $100 million in payments. Criminals using Hive’s ransomware-as-a-service tools targeted a wide range of businesses and critical infrastructure, including government, manufacturing and especially health care.
Though the FBI offered decryption keys to some 1,300 victims globally, Wray said only about 20 percent reported potential issues to law enforcement.
“Here, fortunately, we were still able to identify and help many victims who didn’t report. But that is not always the case,” Wray said. “When victims report attacks to us, we can help them and others, too.”
Victims sometimes quietly pay ransoms without notifying authorities — even if they’ve quickly restored networks — because the data stolen from them could be extremely damaging to them if leaked online. Identity theft is among the risks.
John Hultquist, the head of threat intelligence at the cybersecurity firm Mandiant, said the Hive disruption won’t cause a major drop in overall ransomware activity but is nonetheless “a blow to a dangerous group.”
“Unfortunately, the criminal marketplace at the heart of the ransomware problem ensures a Hive competitor will be standing by to offer a similar service in their absence, but they may think twice before allowing their ransomware to be used to target hospitals,” Hultquist said.
But analyst Brett Callow with the cybersecurity firm Emsisoft said the operation is apt to lessen ransomware crooks’ confidence in what has been a very high reward-low risk business. “The information collected may point to affiliates, launderers and others involved in the ransomware supply chain.”
Allan Liska, an analyst with Recorded Future, another cybersecurity outfit, predicted indictments, if not actual arrests, in the next few months.
There are few positive indicators in the global fight against ransomware, but here’s one: An analysis of cryptocurrency transactions by the firm Chainalysis found ransomware extortion payments were down last year. It tracked payments of at least $456.8 million, down from $765.6 million in 2021. While Chainalysis said the true totals are certainly much higher, payments were clearly down. That suggests more victims are refusing to pay.
The Biden administration got serious about ransomware at its highest levels two years ago after a series of high-profile attacks threatened critical infrastructure and global industry. In May 2021, for instance, hackers targeted the nation’s largest fuel pipeline, causing the operators to briefly shut it down and make a multimillion-dollar ransom payment, which the US government later largely recovered.
A global task force involving 37 nations began work this week. It is led by Australia, which has been particularly hard-hit by ransomware, including a major medical insurer and telecom. Conventional law enforcement measures such as arrests and prosecutions have done little to frustrate the criminals. Australia’s interior minister, Clare O’Neil, said in November that her government was going on the offense, using cyber-intelligence and police agents to ” find these people, hunt them down and debilitate them before they can attack our country.”
The FBI has obtained access to decryption keys before. It did so in the case of a major 2021 ransomware attack on Kaseya, a company whose software runs hundreds of websites. It took some heat, however, for waiting several weeks to help victims unlock afflicted networks.


Pickup truck driver killed by police after driving through Texas mall and injuring 5

Updated 4 sec ago
Follow

Pickup truck driver killed by police after driving through Texas mall and injuring 5

  • The truck crashed into the department store in Killeen, 109 kilometers north of the state capital Austin
  • Emergency medical services transported four victims to area hospitals and another traveled to a hospital separately
KILLEEN, Texas: A pickup truck driver fleeing police careened through the doors of a JCPenney store in Texas and continued through a busy mall, injuring five people before he was fatally shot by officers, authorities said.
The truck crashed into the department store in Killeen, about 68 miles (109 kilometers) north of the state capital Austin, around 5:30 p.m. Saturday and continued into the building, striking people as it went, Sgt. Bryan Washko of the Texas Department of Public Safety said in an evening news briefing.
Emergency medical services transported four victims from the mall to area hospitals and another traveled to a hospital separately. They ranged in age from 6 to 75 years old and their conditions were not immediately known, he said.
The chase began around 5 p.m. on Interstate 14 in Belton, about 20 miles (30 kilometers) from Killeen, after authorities received calls about an erratic driver in a black pickup, Ofelia Miramontez of the Killeen Police Department said.
The driver then pulled off the road and drove into the parking lot of the mall.
“The suspect drove through the doors and continued to drive through the JCPenney store, striking multiple people,” Washko said. “The trooper and the Killeen police officer continued on foot after this vehicle, which was driving through the store, actively running people over. He traveled several hundred yards.”
Officers from the state public safety department, Killeen and three other law enforcement agencies “engaged in gunfire to eliminate this threat,” Washko said.
One of the officers who traded gunfire with the suspect was working as a security guard at the mall and others were off duty, he said.
Washko did not have information about the suspect’s identity at the time of the briefing.
Witnesses interviewed by local news outlets outside the mall said they heard multiple gunshots and saw people fleeing through the mall.

India child marriage crackdown reaches nearly 5,000 arrests

Updated 25 min 28 sec ago
Follow

India child marriage crackdown reaches nearly 5,000 arrests

  • India is home to more than 220 million child brides, according to the United Nations
  • The legal marriage age in India is 18 but millions of children are forced to tie the knot when they are younger

GUWAHATI, India: A crackdown on illegal child marriages in India’s northeast has resulted in nearly 5,000 arrests, after 416 people were detained in the latest police sweep, a minister said Sunday.
“We will continue to take bold steps to end this social evil,” Himanta Biswa Sarma, chief minister of Assam state, said in a statement.
“Assam continues its fight against child marriage,” he added, saying raids have been carried out overnight and that those arrested would be produced in court on Sunday.
India is home to more than 220 million child brides, according to the United Nations, but the number of child weddings has fallen dramatically this century.
Assam state had already arrested thousands in earlier abolition drives that began in February 2023, including parents of married couples and registrars who signed off on underage betrothals.
It takes the total now arrested to more than 4,800 people.
Sarma has campaigned on a platform of stamping out child marriages completely in his state by 2026.
The legal marriage age in India is 18 but millions of children are forced to tie the knot when they are younger, particularly in poorer rural areas.
Many parents marry off their children in the hope of improving their financial security.
The results can be devastating, with girls dropping out of school to cook and clean for their husbands, and suffering health problems from giving birth at a young age.
In a landmark 2017 judgment, India’s top court said that sex with an underage wife constituted rape, a ruling cheered by activists.


Russian defense ministry says it downed 42 Ukrainian drones overnight

Updated 27 min 54 sec ago
Follow

Russian defense ministry says it downed 42 Ukrainian drones overnight

  • The heads of the Rostov and Bryansk regions said there were no casualties or damage after the latest drone attacks

MOSCOW: Russia’s Defense Ministry said on Sunday its air defense systems destroyed 42 Ukrainian drones over five Russian regions during the night.
Twenty drones were shot down over the Oryol region, eight drones each were destroyed in the Rostov and Bryansk regions, five in the Kursk region and one over Krasnodar Krai, the ministry said in a post on the Telegram messaging app.
One attack triggered a fire at a fuel infrastructure facility in the village of Stalnoi Kon, said Andrei Klychkov, the governor of Oryol.
“Fortunately, thanks to the quick response, the consequences of the attack were avoided — the fire was promptly localized and is now fully extinguished. There were no casualties or significant damage,” he said.
It was the second week in a row where fuel infrastructure facilities in Oryol have been attacked.
The heads of the Rostov and Bryansk regions said there were no casualties or damage after the latest drone attacks.
Reuters could not independently verify the battlefield accounts.


China says US is ‘playing with fire’ after latest military aid for Taiwan

Updated 22 December 2024
Follow

China says US is ‘playing with fire’ after latest military aid for Taiwan

  • US President Joe Biden authorized Saturday the provision of up to $571 million for Taiwan
  • Separately, the Defense Department said Friday that $295 million in military sales had been approved

BEIJING: The Chinese government protested Sunday the latest American announcements of military sales and assistance to Taiwan, warning the United States that it is “playing with fire.”
US President Joe Biden authorized Saturday the provision of up to $571 million in Defense Department material and services and in military education and training for Taiwan. Separately, the Defense Department said Friday that $295 million in military sales had been approved.
A Chinese Foreign Ministry statement urged the US to stop arming Taiwan and stop what it called “dangerous moves that undermine peace and stability in the Taiwan Strait.”
Taiwan is a democratic island of 23 million people that the Chinese government claims as its territory and says must come under its control. US military sales and assistance aim to help Taiwan defend itself and deter China from launching an attack.
The $571 million in military assistance comes on top of Biden’s authorization of $567 million for the same purposes in late September. The military sales include $265 million for about 300 tactical radio systems and $30 million for 16 gun mounts.
Taiwan’s Foreign Ministry welcomed the approval of the two sales, saying in a social media post on X that it reaffirmed the US government’s “commitment to our defense.”


New hope for flight MH370 families as Malaysia agrees to resume search

Updated 22 December 2024
Follow

New hope for flight MH370 families as Malaysia agrees to resume search

  • Plane carrying 239 people went missing en route from Kuala Lumpur to Beijing in March 2014
  • Families say they hope new search operation will offer ‘long-awaited answers and closure’

KUALA LUMPUR: The families of Malaysia Airlines flight MH370 passengers have welcomed with renewed hope the announcement of a new search for the aircraft, which disappeared more than 10 years ago in one of the greatest mysteries in aviation history.

Flight MH370, a Boeing 777 with 239 people on board, went missing en route from Kuala Lumpur to Beijing in 2014.

The search became the most expensive operation in aviation history but ended inconclusively in 2018, leaving the families of those on board still haunted by the tragedy.

On Friday, Malaysia’s Transport Minister Anthony Loke announced that he hoped to “give closure to the families” as the government agreed to allow private contractor Ocean Infinity, which was the last to try to locate the plane, to resume search efforts.

He told reporters that the operation would focus on a new area spanning 15,000 sq. km in the southern Indian Ocean — a development raising hope among relatives of passengers and crew aboard flight MH370.

“The significance of this renewed search cannot be overstated. For the families of passengers, the scientific community and global civil aviation safety, it offers renewed hope for long-awaited answers and closure,” Voice 370, the association representing them, said in a statement.

“We, the next of kin, have endured over a decade of uncertainty, and we hope that the terms of the renewed search are finalized at the earliest and the decks are cleared for the search to begin.

“We continue to hope that our wait for answers is met.”

Ocean Infinity, the private underwater exploration firm that will undertake the $70 million search, was briefly involved in the 2018 efforts after a three-year operation covering 120,000 sq. km of the Indian Ocean failed to locate the aircraft and was suspended in 2017.

The new agreement was met on a no-find, no-fee basis, meaning that Ocean Infinity will be paid only when the wreckage is found.

“We are encouraged by Ocean Infinity’s readiness to deploy their advanced fleet, including sophisticated vessels, AUVs and cutting-edge imaging technologies,” Voice 370 said.

“We gather that the company has followed this up with thorough due diligence, analyzing all available data, and alternative scenarios proposed by independent researchers and recommendations on potential search areas.”

Flight MH370 took off from Kuala Lumpur in the early hours of March 8, 2014 and lost communication with air traffic control less than an hour later. Military radar showed the aircraft had deviated from its planned path. It remains unclear why that happened.

Many conspiracy theories have emerged to explain the aircraft’s disappearance, ranging from suspicions of the captain’s suicide to concerns over the 221 kg of lithium-ion batteries in the plane’s cargo, as well as the involvement of passengers, two of whom were found traveling on stolen passports.

When the probe was suspended, Kok Soo Chon, head of the MH370 safety investigation team, told reporters in July 2018 that his team was “unable to determine the real cause for disappearance of MH370” and “the answer can only be conclusive if the wreckage is found.”