Ransomware group REvil disappears from the internet

The Russia-linked ransomware group behind some of the biggest recent cyberattacks has disappeared from the internet. According to CNBC, Reuters and The Washington Post, the websites operated by the group REvil went down in the early hours of Tuesday. Dmitri Alperovitch, former chief technology officer of the cyber firm CrowdStrike, told The Post that the group’s blog in the dark web is still reachable. However, its critical sites victims use to negotiate with the group and to receive decryption tools if they pay up are no longer available. Visitors to those websites now see a message that says “A server with the specified hostname could not be found.”

REvil took responsibility for a recent string of ransomware attacks that affected around 800 to 1,500 businesses worldwide, including schools. It demanded $70 million to restore the data it stole and encrypted. Before that, experts linked the group to the ransomware attacks on IT management software giant Kaseya and beef supplier JBS, which chose to pay US$11 million to get its data back. 

It’s unclear why REvil’s websites aren’t accessible anymore. As Reuters mentioned, ransomware gangs tend to vanish and rebrand in case they attract too much attention. President Biden recently revealed that he told Russian President Vladimir Putin that he expects his government to act on ransomware attacks coming from his country. When asked if the US would attack the servers Russian cybercriminals use to hijack American networks, Biden answered with a resounding “Yes.”

Alperovitch told The Post that it doesn’t look like REvil’s servers were attacked, which means it’s unlikely a an offensive cyber operation launched by US authorities. Kurtis Minder, the founder of threat intelligence firm GroupSense, told Reuters that if REvil’s sites going down truly was the result of an offensive operation mounted by the US government, he hopes that “collateral damage was a consideration.” Bad actors hold the key to the data they take ransom, and victims would have a tough time recovering theirs if that key gets destroyed or lost.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechNewsBoy.com is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.