Hive Ransomware Network Dismantled by American, European Law Enforcement
Law enforcement authorities from over a dozen countries in Europe and North America have taken part in disrupting the activities of the Hive ransomware group, the U.S. Justice Department and Europol announced. Hive is be...
Law enforcement authorities from over a dozen countries in Europe and North America have taken part in disrupting the activities of the Hive ransomware group, the U.S. Justice Department and Europol announced. Hive is believed to have targeted various organizations worldwide in the past couple of years, often extorting payments in cryptocurrency.
Captured Decryption Keys Helped Hive Victims Avoid Paying $130 Million in RansomRansomware network Hive, which has had around 1,500 victims in more than 80 countries, has been hit in a months-long disruption campaign, the U.S. Department of Justice (DOJ) and the European Union Agency for Law Enforcement Cooperation (Europol) revealed. A total of 13 nations participated in the operation, including EU member states, the U.K. and Canada.
Hive has been identified as a major cybersecurity threat as the ransomware has been used by affiliated actors to compromise and encrypt data and computer systems of government facilities, oil multinationals, IT and telecom companies in the EU and U.S., Europol said. Hospitals, schools, financial firms, and critical infrastructure have been targeted, the DOJ noted.
It has been one of the most prolific ransomware strains, Chainalysis pointed out, which has collected at least $100 million from victims since its launch in 2021. A recent report by the blockchain forensics company unveiled that revenue from such attacks has decreased last year, with a growing number of affected organizations refusing to pay the demanded ransoms.
According to the announcements by the law enforcement authorities, the U.S. Federal Bureau of Investigation (FBI) penetrated Hive’s computers in July 2022 and captured its decryption keys, providing them to victims around the world which prevented them from paying another $130 million.
Working with the German Federal Police and the Dutch High Tech Crime Unit, the Bureau has now seized control over the servers and websites that Hive used to communicate with its members and the victims, including the darknet domain where the stolen data was sometimes posted. FBI Director Christopher Wray was quoted as stating:
The coordinated disruption of Hive’s computer networks … shows what we can accomplish by combining a relentless search for useful technical information to share with victims.
The Hive ransomware was created, maintained and updated by developers while being employed by affiliates in a ‘ransomware-as-a-service’ (RaaS) double extortion model, Europol explained. The affiliates would initially copy the data and then encrypt the files before asking for a ransom to decrypt the information and not publish it on the leak site.
The attackers exploited various vulnerabilities and used a number of methods, including single factor logins via Remote Desktop Protocol (RDP), virtual private networks (VPNs), and other remote network connection protocols as well as phishing emails with malicious attachments, the law enforcement agencies detailed.
Do you expect police authorities around the world to dismantle more ransomware networks in the near future? Tell us in the comments section below.
Original source
Read on Bitcoin NewsRelated market context
Crypto Laundering Network Linked To Ransomware Gangs Dismantled By Law Enforcement
TL;DR Chainalysis says law enforcement has dismantled AudiA6, a crypto laundering network linked to ransomware and darknet activit...
Coinbase Quantum Report Warns Millions Of Bitcoin Could Face Future Security Risks
TL;DR Coinbase’s Quantum Advisory Council published a report on post-quantum migration and abandoned coins. The report estimates t...
Ripple CEO Accused Jamie Dimon of Lying About CLARITY Act And Called Out $20Bn Reason Why
Ripple CEO Brad Garlinghouse went directly at JPMorgan chief Jamie Dimon on Fox Business Wednesday, accusing him of ‘intentional m...
LG Electronics Tests Onchain Advertising Network On Arbitrum
TL;DR LG Electronics is piloting an onchain advertising network on Arbitrum. The project is designed to make ad performance more v...
Coinbase Council Warns 7 Million Bitcoin May Face Future Quantum Risk
TL;DR Coinbase’s Quantum Advisory Council says post-quantum migration planning should begin before quantum attacks become practica...
Sky Governance Proposal Seeks To Double USDC PSM Buffer To $800 Million
TL;DR BA Labs has proposed doubling key LITE-PSM-USDC-A parameters in the Sky stablecoin system from 400 million to 800 million. T...