REvil 그룹의 Darknet 사이트가 다시 작동합니다: 러시아인이 사이버 범죄자를 야생으로 풀어 놓으십시오.?

Information security specialists have noticed that the darknet sites of the REvil hack group, which stopped working in early 2022, are active again. The sites are redirecting to another ransomware campaign, with the new site listing past victims of the REvil attacks as well as new ones.

악마 ceased operations in January 2022 후 FSB announced the arrest of 14 people associated with the hack group. 동시에, it was reported thatthe basis for the search activities was the appeal of the competent US authorities.

Then the Tverskoy Court of Moscow took into custody eight alleged members of the hack group. All of them were charged with the acquisition and storage of electronic funds intended for the illegal transfer of funds made by an organized group (Section 2 Paragraph 187 of the Criminal Code of the Russian Federation). The punishment under this article is up to seven years in prison.

그런데, there is also a struggle within the hacker community: 예를 들면, we reported that LV malware uses binaries of hack group REvil without permission.

블 리핑 컴퓨터 writes that the first to notice the activity of the REvil sites were the information security specialists pancak3Soufiane Tahiri. The fact is that the newsite for leaksREvil began to be advertised through the Russian-speaking forum-marketplace RuTOR (not to be confused with the torrent tracker of the same name).

The new site is hosted on a different domain but linked to the original REvil site that was in use when the group was still active.journalists of Bleeping Computer told.

The site provides detailed working conditions for “partners” who allegedly receive an improved version of the REvil malware and share the ransom with the developers of the ransomware in an 80/20 ratio.

그만큼 26 pages of the site also list companies that have suffered from ransomware, most of which are old victims of REvil. Only the last two attacks appear to be related to the new campaign, 과 one of the victims is Oil India oil and gas company.

Journalists note that back in January of this year, shortly before the termination of REvil, the researcher MalwareHunterTeam 썼다 that since mid-December last year, he has been observing the activity of another ransomware group, 그만큼 Ransom Cartel, which seems to be somehow connected with the REvil ransomware.

그런데, we noted that according to 기록된 미래 전문가, ALPHV의 창시자 (검은 고양이) was previously a member of the well-known hacker group REvil.

나중에, the same MalwareHunterTeam researcher noticed 포티넷 “leak siteREvil was active from April 5 에게 10, but contained no content. It started filling up about a week later. The MalwareHunterTeam also found that the RSS feed has aCorp Leaksstring, which used to be used by the now defunct Nefilim 해킹 그룹.

REvil 다크넷 사이트

동시에, Bleeping Computer claims that the new blog and payment sites are running on different servers, and the blog contains a cookie named DEADBEEF, which was previously used by another extortionist groupTeslaCrypt.

REvil 다크넷 사이트

본질적으로, the operation of the new redirects means that someone other than law enforcement has access to Tor’s private keys, which allow them to make the necessary changes.

According to the publication, there is already an active discussion on Russian-speaking hack forums about whether the new operation is a scam, a lure of the authorities, or is it really a new proposal from some REvil members who are trying to fix a damaged reputation.

현재, there are several ransomware that use a modified REvil malware, and some of them even impersonate the original hack group. These include LV, who used the REvil ransomware even before law enforcement became interested in the hack group, and the Ransom Cartel, which is somehow connected to REvil, but how exactly is not yet clear.

헬가 스미스

저는 항상 컴퓨터 과학에 관심이있었습니다, 특히 데이터 보안 및 테마, 요즘은 "데이터 과학", 10 대 초반부터. 편집장으로 바이러스 제거 팀에 오기 전, 저는 여러 회사에서 사이버 보안 전문가로 일했습니다., 아마존 계약자 중 한 명 포함. 또 다른 경험: 나는 Arden과 Reading 대학에서 가르치고 있습니다..

회신을 남겨주

이 사이트는 스팸을 줄이기 위해 Akismet 플러그를 사용. 귀하의 코멘트 데이터가 처리되는 방법 알아보기.

맨 위로 버튼