US infiltrates big ransomware gang: ‘We hacked the hackers’

US Attorney General Merrick Garland, with FBI Director Christopher Wray (R) and Deputy Attorney General Lisa Monaco (L), announces the shutting down of the Hive ransomware operation on January 26, 2023. (AFP)
Short Url
Updated 27 January 2023
Follow

US infiltrates big ransomware gang: ‘We hacked the hackers’

  • Gang identified as Hive among the world’s top five ransomware networks and has heavily targeted health care
  • Hive, working with German and other partners, was estimated to have victimized some 1,300 companies globally

WASHINGTON: The FBI and international partners have at least temporarily disrupted the network of a prolific ransomware gang they infiltrated last year, saving victims including hospitals and school districts a potential $130 million in ransom payments, Attorney General Merrick Garland and other US officials announced Thursday.
“Simply put, using lawful means we hacked the hackers,” Deputy Attorney General Lisa Monaco said at a news conference.
Officials said the targeted syndicate, known as Hive, is among the world’s top five ransomware networks and has heavily targeted health care. The FBI quietly accessed its control panel in July and was able to obtain software keys it used with German and other partners to decrypt networks of some 1,300 victims globally, said FBI Director Christopher Wray.
How the takedown will affect Hive’s long-term operations is unclear. Officials announced no arrests but said, to pursue prosecutions, they were building a map of the administrators who manage the software and the affiliates who infect targets and negotiate with victims.
“I think anyone involved with Hive should be concerned because this investigation is ongoing,” Wray said.
On Wednesday night, FBI agents seized computer servers in Los Angeles used to support the network. Two Hive dark web sites were seized: one used for leaking data of non-paying victims, the other for negotiating extortion payments.
“Cybercrime is a constantly evolving threat, but as I have said before, the Justice Department will spare no resource to bring to justice anyone anywhere that targets the United States with a ransomware attack,” Garland said.

 

He said the infiltration, led by the FBI’s Tampa office, allowed agents in one instance to disrupt a Hive attack against a Texas school district, stopping it from making a $5 million payment.
It’s a big win for the Justice Department. Ransomware is the world’s biggest cybercrime headache with everything from Britain’s postal service and Ireland’s national health network to Costa Rica’s government crippled by Russian-speaking syndicates that enjoy Kremlin protection.
The criminals lock up, or encrypt, victims’ networks, steal sensitive data and demand large sums. Their extortion has evolve to where data is pilfered before ransomware is activated, then effectively held hostage. Pay up in cryptocurrency or it is released publicly.
As an example of a Hive sting, Garland said it kept one Midwestern hospital in 2021 from accepting new patients at the height of the COVID-19 epidemic.
The online takedown notice, alternating in English and Russian, mentions Europol and German law enforcement partners. The German news agency dpa quoted prosecutors in Stuttgart as saying cyber specialists in the southwestern town of Esslingen were decisive in penetrating Hive’s criminal IT infrastructure after a local company was victimized.
In a statement, Europol said companies in more than 80 countries, including oil multinationals, have been compromised by Hive and that law enforcement from 13 countries was in on the infiltration.
A US government advisory last year said Hive ransomware actors victimized over 1,300 companies worldwide from June 2021 through November 2022, netting about $100 million in payments. Criminals using Hive’s ransomware-as-a-service tools targeted a wide range of businesses and critical infrastructure, including government, manufacturing and especially health care.
Though the FBI offered decryption keys to some 1,300 victims globally, Wray said only about 20 percent reported potential issues to law enforcement.
“Here, fortunately, we were still able to identify and help many victims who didn’t report. But that is not always the case,” Wray said. “When victims report attacks to us, we can help them and others, too.”
Victims sometimes quietly pay ransoms without notifying authorities — even if they’ve quickly restored networks — because the data stolen from them could be extremely damaging to them if leaked online. Identity theft is among the risks.
John Hultquist, the head of threat intelligence at the cybersecurity firm Mandiant, said the Hive disruption won’t cause a major drop in overall ransomware activity but is nonetheless “a blow to a dangerous group.”
“Unfortunately, the criminal marketplace at the heart of the ransomware problem ensures a Hive competitor will be standing by to offer a similar service in their absence, but they may think twice before allowing their ransomware to be used to target hospitals,” Hultquist said.
But analyst Brett Callow with the cybersecurity firm Emsisoft said the operation is apt to lessen ransomware crooks’ confidence in what has been a very high reward-low risk business. “The information collected may point to affiliates, launderers and others involved in the ransomware supply chain.”
Allan Liska, an analyst with Recorded Future, another cybersecurity outfit, predicted indictments, if not actual arrests, in the next few months.
There are few positive indicators in the global fight against ransomware, but here’s one: An analysis of cryptocurrency transactions by the firm Chainalysis found ransomware extortion payments were down last year. It tracked payments of at least $456.8 million, down from $765.6 million in 2021. While Chainalysis said the true totals are certainly much higher, payments were clearly down. That suggests more victims are refusing to pay.
The Biden administration got serious about ransomware at its highest levels two years ago after a series of high-profile attacks threatened critical infrastructure and global industry. In May 2021, for instance, hackers targeted the nation’s largest fuel pipeline, causing the operators to briefly shut it down and make a multimillion-dollar ransom payment, which the US government later largely recovered.
A global task force involving 37 nations began work this week. It is led by Australia, which has been particularly hard-hit by ransomware, including a major medical insurer and telecom. Conventional law enforcement measures such as arrests and prosecutions have done little to frustrate the criminals. Australia’s interior minister, Clare O’Neil, said in November that her government was going on the offense, using cyber-intelligence and police agents to ” find these people, hunt them down and debilitate them before they can attack our country.”
The FBI has obtained access to decryption keys before. It did so in the case of a major 2021 ransomware attack on Kaseya, a company whose software runs hundreds of websites. It took some heat, however, for waiting several weeks to help victims unlock afflicted networks.


Republican House bill would jack up cost of US solar home systems, PV panel makers warn

Updated 11 sec ago
Follow

Republican House bill would jack up cost of US solar home systems, PV panel makers warn

  • Proposed measure would scrap 30 percent tax credit for homeowners with solar panels
  • Bill in line with Trump move to undo Biden-era clean energy program

Companies that put solar panels on US homes say a Republican budget bill advanced in Congress this week would deal a massive blow to the industry by eliminating a generous subsidy for homeowners that had buttressed the industry’s growth.
The bill would scrap a 30 percent federal credit for taxpayers who put up rooftop systems, stifling an industry that has grown ten-fold over the last decade and which now employs more than 100,000 workers, industry players said.
“It certainly is a giant setback,” said Charlie Hadlow, president of EnergySage, an online solar marketplace. “I have solar installers in our large network passing around the contact information for bankruptcy attorneys. That’s not alarmist, that’s happening.”
Many of the biggest residential solar markets are in states that voted for President Donald Trump, including Texas, Florida and Arizona, according to the Solar Energy Industries Association trade group.
The House of Representatives Ways and Means Committee voted this week to allow the 25D tax credit to expire at the end of this year, nine years earlier than planned, as part of a Republican effort to roll back subsidies from former President Joe Biden’s signature climate law, the Inflation Reduction Act.
A spokesperson for Republicans on the committee did not immediately respond to a request for comment.
The bill still has several hurdles to clear before getting a broad package of tax cuts, spending hikes and safety-net reductions through Congress.
The White House did not immediately respond to a request for comment. Trump wants to undo federal regulations and programs introduced by Biden that are aimed at expanding clean energy and combating climate change.
More than half of residential installations qualify for the 25D tax credit, according to EnergySage, which estimates that rooftop systems will be about $8,000 or $9,000 more expensive without it.
The subsidy has been critical for small installers whose customers pay cash or take out loans and then claim the credit on their tax returns.
For panels that are owned by a third party, such as a bank, and leased to homeowners, system owners are able to claim a separate tax credit that the House bill would leave in place until 2032 but start to phase out in 2029.
That market is dominated by large players like Sunrun.
“You want to just place a larger burden on the regular Joe who pays taxes? It doesn’t seem fair,” said Jack Ramsey, CEO of Altsys Solar in Tulare, California.
Ramsey anticipates cutting his nine-person staff to four or five people if the credit is eliminated.
At the end of 2024, the US boasted 36 gigawatts of residential solar capacity, up from 3 GW in 2014 and a level equivalent to a third of the nation’s nuclear power capacity.
Rooftop solar accounts for more than a third of solar industry jobs, according to the Interstate Renewable Energy Council.
Rob Kaercher, CEO of Absolute Solar in Lansing, Michigan, has 24 employees and wants to hire more, but will not if the credit goes away.
“I strongly urge the credits to be maintained, because it would do a tremendous amount for local businesses just like ours to be able to continue to hire and grow,” Kaercher told reporters.
The move to eliminate the credit caught many in the industry off guard.
Thomas Clark, the director of marketing and communications of Northstone Solar in Whitefish, Montana, met with staff from his state’s Congressional delegation in Washington earlier this year and came away from the meeting feeling the credit was safe.
“Obviously this happening so quickly after those meetings really hurts as a constituent,” Clark said.


Macron calls for peace in first talk with new pope

Updated 38 min 2 sec ago
Follow

Macron calls for peace in first talk with new pope

PARIS: French President Emmanuel Macron said on Thursday he had called Pope Leo XIV and talked about efforts to reach peace in Ukraine and Gaza in his first conversation with the new pontiff.
In their “first exchange,” the pair “addressed the efforts to let the weapons fall silent wherever conflicts rage in the world, and in particular for a solid and lasting peace in Ukraine and Gaza,” Macron said on X.
“We share the ambition to reconcile the fight against poverty and the protection of the planet,” the French leader said, adding that he had “once again congratulated” the pontiff on his election as head of the Catholic Church last week.
While Macron is not scheduled to join the ranks of the world leaders attending Pope Leo’s inaugural mass in Rome on Sunday morning, France’s Prime Minister Francois Bayrou is due to attend.


Nigeria army head vows to counter jihadist attacks

Updated 48 min 20 sec ago
Follow

Nigeria army head vows to counter jihadist attacks

MAIDUGURI, Nigeria: Nigeria’s top military officer on Thursday told troops in a region battling increased jihadist unrest that the attacks would be quickly resolved.
The Islamic State West Africa Province group and its rival Boko Haram have intensified assaults on military bases in recent weeks, notably in the northeastern state of Borno, epicenter of an insurgency dating back to 2009.
According to an AFP tally, at least 10 bases have been attacked in two months. At least 100 people, including civilians, were killed in attacks in April.
“Actions have been taken to ensure that we address the series of attacks,” chief of defense staff General Christopher Musa told troops in Borno’s capital Maiduguri, promising new material was being drafted in.
Musa said conflict in the Sahel states including Mali, Chad and Niger “has put a lot of pressure on Nigeria and that’s why you see recent attacks have occurred.”
“Whatever is going on is just for a short while,” he said.
Musa suggested fencing Nigeria’s borders, saying “there are countries that have fenced over a 1,500 kilometer (930 mile) stretch” — roughly the length of the Nigeria-Niger frontier.
While violence has fallen from its 2014-2015 peak, the governor of Borno recently warned that the military was losing ground to jihadists, and the latest attacks have put the conflict back in the spotlight.
More than 40,000 people have been killed and two million displaced in northeast Nigeria since 2009, according to the United Nations.
A Multinational Joint Task Force, a coalition created by Nigeria, Niger, Cameroon, Benin and Chad to fight cross-border armed groups, has been hampered by the withdrawal of Niger and threats by Chad to do the same.
According to a recent Nigerian intelligence report seen by AFP, there are also internal problems.
Late payment of salaries “has been a recurring problem,” particularly in the northeast, it said.
The report warned of “frustration and demotivation among security personnel, which could potentially lead to mutinies or unrest, if not urgently addressed.”
President Bola Tinubu this week called for the creation of a “forest guards” unit “to flush out terrorists and criminal gangs.”
Nigeria’s vast, often inaccessible forests have become havens for jihadist and armed criminal groups.
While the Nigerian army often works with local self-defense groups, questions remain over how the proposed forest guard be financed, work with existing security forces and even how long it would take to set up.


13 hurt when car plows into crowd before Spanish footbal match

Updated 48 min 31 sec ago
Follow

13 hurt when car plows into crowd before Spanish footbal match

  • Police ruled case as an accident, described all injuries as "minor"
  • Driver arrested on suspicion of dangerous driving and causing injury

BARCELONA: At least 13 people were hurt when a driver lost control and plowed into a crowd gathered outside a football match between RCD Espanyol and city rivals FC Barcelona, police said on Thursday.
Police said people were hurt when the vehicle rammed into the crowd outside RCD Españyol soccer stadium in Barcelona at the start of the game.
Police added in a statement on social media site X that the incident did not present any danger to the crowd inside the stadium.
Salvador Illa, the Catalan regional president, said on Thursday all the injuries were “minor” and ruled out any deliberate attack.
The driver has been arrested on suspicion of dangerous driving and causing injury.


New Royal Navy chief under renewed scrutiny over Afghanistan war crimes evidence

Updated 15 May 2025
Follow

New Royal Navy chief under renewed scrutiny over Afghanistan war crimes evidence

  • Gen. Gwyn Jenkins previously accused of failing to report evidence of war crimes committed by British forces
  • It is also alleged he oversaw rejection of hundreds of resettlement applications from Afghans who served alongside British troops against the Taliban

LONDON: The man chosen as the new head of the UK’s Royal Navy was previously accused of failing to report evidence of war crimes allegedly committed by British forces in Afghanistan.

Gen. Sir Gwyn Jenkins, who was appointed on Thursday, also faced allegations this week that he oversaw the rejection of hundreds of resettlement applications from former Afghan special forces members who served alongside British troops against the Taliban, The Guardian newspaper reported.

Jenkins replaces Adm. Ben Key, who stepped down last week over allegations of misconduct.

The new navy chief previously led UK Special Forces in Afghanistan during the war against the Taliban. That conflict is under renewed scrutiny in Britain following recent fresh allegations of war crimes involving members of Britain’s elite Special Air Service and Special Boat Service.

In 2023, it emerged that Jenkins had been warned in writing in 2011 that SAS troops had claimed to have executed handcuffed detainees in Afghanistan. Rather than refer this evidence to the Royal Military Police, the BBC reported at the time, Jenkins placed the documents in a safe. However, The Telegraph newspaper reported that Jenkins did pass the evidence up the chain of command at the time.

This week, an investigation by the BBC current affairs program “Panorama” revealed that Jenkins personally appointed an officer under his command to assess the Afghan resettlement applications. Thousands of former elite Afghan soldiers were rejected, despite credible evidence of their service alongside British counterparts.

The UK’s Ministry of Defence said it was “not appropriate … to comment on allegations which may be within the scope of the statutory inquiry,” referring to a public inquiry underway in the UK to investigate the war crimes allegations.

There was “no evidence” that Afghan resettlement applications were rejected to prevent the former soldiers from giving evidence to the war crimes inquiry, it added.

Defence Secretary John Healey on Thursday described Jenkins as a “proven leader with a distinguished career in both the military and at the core of government.”

He added: “I know he will deliver in this pivotal role, making Britain secure at home and strong abroad.”

Sarah Atherton, a former Tory MP who sat on the Defence Select Committee, told The Telegraph: “Military personnel, especially senior leaders, are held to high ethical and behavior standards.

“If somebody is facing an allegation … I know it’s alleged, but it’s just very strange to appoint someone who is in this position, given the circumstances. That is bizarre.”

Jenkins said after his appointment that he wanted to “accelerate” the Royal Navy’s return to a “war fighting force that is ready for conflict.”