{"id":24555,"date":"2023-01-27T18:53:11","date_gmt":"2023-01-27T23:53:11","guid":{"rendered":"http:\/\/worldjusticenews.com\/news\/?p=24555"},"modified":"2023-01-27T18:53:11","modified_gmt":"2023-01-27T23:53:11","slug":"us-hacks-back-against-hive-ransomware-crew","status":"publish","type":"post","link":"https:\/\/worldjusticenews.com\/news\/2023\/01\/27\/us-hacks-back-against-hive-ransomware-crew\/","title":{"rendered":"US hacks back against Hive ransomware crew"},"content":{"rendered":"<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\"><b class=\"ssrcss-hmf8ql-BoldText e5tfeyi3\">The US has revealed it infiltrated a prolific cyber-crime gang to secretly sabotage their hacking attacks for more than six months.<\/b><\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The Department of Justice (DOJ) revealed the FBI gained deep access to the Hive ransomware group in late July 2022.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Officers were able to warn victims of impending attacks.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">They also gave more than 300 decryption keys to those hacked, saving them, they estimate, more than $130m (\u00a3105m).<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Ransomware gangs use malicious software that encrypts victims&#8217; files, locking them up and making them inaccessible unless a ransom is paid to obtain a decryption key.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The US estimates Hive and its affiliates collected over $100m (\u00a381m) from more than 1,500 victims, including hospitals, school districts, financial companies and critical infrastructure, in more than 80 countries around the world. One hospital was left unable to accept new patients.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The FBI says it worked with local law enforcement agencies to help victims recover including the UK&#8217;s National Crime Agency which says it gave around 50 UK organisations decryptor keys to overcome the hacks.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The US said on Thursday that it ended the operation by taking down Hive&#8217;s websites and communication networks with the help of police forces in Germany and the Netherlands.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Attorney General Merrick Garland said: &#8220;Last night, the Justice Department dismantled an international ransomware network responsible for extorting and attempting to extort hundreds of millions of dollars from victims in the United States and around the world.&#8221;<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Deputy Attorney General Lisa O Monaco said: &#8220;Simply put, using lawful means, we hacked the hackers.&#8221;<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The DOJ said it would pursue those behind Hive until they were brought to justice.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">&#8220;A good covert operation can degrade confidence in operational security and inject suspicion among actors,&#8221; Mandiant Threat Intelligence head John Hultquist said.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">But he added: &#8220;Until the group is arrested, they will never truly be gone. They will have to reconstitute, which takes time, but I&#8217;ll bet they reappear in time.&#8221;<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-18mjolk-ComponentWrapper ep2nwvo1\" data-component=\"image-block\">\n<figure class=\"ssrcss-wpgbih-StyledFigure e34k3c23\">\n<div class=\"ssrcss-ab5fd8-StyledFigureContainer e34k3c21\"><span class=\"ssrcss-1hq4gmv-Placeholder e16icw910\"><picture><source srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg.webp 240w, https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg.webp 320w, https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg.webp 480w, https:\/\/ichef.bbci.co.uk\/news\/624\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg.webp 624w, https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg.webp 800w, https:\/\/ichef.bbci.co.uk\/news\/976\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg.webp 976w\" type=\"image\/webp\" \/><img loading=\"lazy\" decoding=\"async\" class=\"ssrcss-evoj7m-Image ee0ct7c0\" src=\"https:\/\/ichef.bbci.co.uk\/news\/976\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg 240w, https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg 320w, https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg 480w, https:\/\/ichef.bbci.co.uk\/news\/624\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg 624w, https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg 800w, https:\/\/ichef.bbci.co.uk\/news\/976\/cpsprodpb\/0963\/production\/_128430420_mediaitem128430419.jpg 976w\" alt=\"The seizure notice which now appears on Hive crew's websites\" width=\"976\" height=\"549\" \/><\/picture><\/span><\/div><figcaption class=\"ssrcss-1mget3o-StyledFigureCaption e34k3c22\">\n<div class=\"ssrcss-y7krbn-Stack e1y4nx260\">The seizure notice which now appears on Hive crew&#8217;s websites (Image: FBI)<\/div>\n<\/figcaption><\/figure>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p>&nbsp;<\/p>\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Researchers and cyber authorities have long accused Russia of harbouring ransomware groups.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">In November 2021, alleged members of the REvil gang were arrested around the world, with US authorities retrieving more than $6m in cryptocurrency in a &#8220;claw back&#8221; hacking operation.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">A similar operation by the US, in June 2021, took the Darkside gang offline and recovered $4.1m in stolen funds.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">And in January of the same year, the ransomware group NetWalker&#8217;s darknet websites were also taken offline and a key affiliate arrested in Canada.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">In all three cases, the hacking groups largely disbanded but are thought to have re-formed into other collectives.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The latest action comes as research suggests ransomware crews saw a 40% drop in earnings, as victims in 2022 are refusing to pay.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-11r1m41-RichTextComponentWrapper ep2nwvo0\" data-component=\"text-block\">\n<div class=\"ssrcss-7uxr49-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">&#8220;We expect initiatives like this to only grow stronger between allied cyber-powers, to ensure that governments, organisations, and citizens will be better protected,&#8221; Nominet government cyber-services expert Kim Wiles said.<\/p>\n<p>Source: <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-64418723\" target=\"_blank\" rel=\"noopener\">bbc.co.uk<\/a><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\">The US has revealed it infiltrated a prolific cyber-crime gang to secretly sabotage their hacking attacks for more than six months. The Department of Justice (DOJ) revealed the FBI gained deep access to the Hive <a class=\"mh-excerpt-more\" href=\"https:\/\/worldjusticenews.com\/news\/2023\/01\/27\/us-hacks-back-against-hive-ransomware-crew\/\" title=\"US hacks back against Hive ransomware crew\">[&#8230;]<\/a><\/div>\n","protected":false},"author":1,"featured_media":24556,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","footnotes":""},"categories":[2,3],"tags":[9134,1172,320,2936,9135,1157,2277,6270,4974],"class_list":{"0":"post-24555","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-usa","9":"tag-cyber-services","10":"tag-fbi","11":"tag-germany","12":"tag-hacking","13":"tag-hive","14":"tag-national-crime-agency","15":"tag-netherlands","16":"tag-ransomware","17":"tag-us-department-of-justice","18":"pmpro-has-access"},"_links":{"self":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/24555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/comments?post=24555"}],"version-history":[{"count":2,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/24555\/revisions"}],"predecessor-version":[{"id":24558,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/24555\/revisions\/24558"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media\/24556"}],"wp:attachment":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media?parent=24555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/categories?post=24555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/tags?post=24555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}