Feel-good story of the week: Two ransomware gangs meet their demise
Full article375 words · extracted from arstechnica.com · click to collapse
“The Trigona ransomware group has poor operational security when it comes to the implementation of Tor sites—although their aim of targeting poorly managed SQL servers is not something we usually see with less technically proficient threat actors,” the post stated.
The timeline of the hack, based on the social media posts, suggests that the breach began roughly eight days ago with the hack of a Confluence server Trigona members used to collaborate. In an interview with the Record, the group said it planned to turn over data it seized to law enforcement authorities.
A takedown two years in the making
The second ransomware gang takedown this week happened to Ragnar Locker, a group that has hacked numerous organizations worldwide. On Friday, Europol said:
In an action carried out between 16 and 20 October, searches were conducted in Czechia, Spain and Latvia. The “key target” of this malicious ransomware strain was arrested in Paris, France, on 16 October, and his home in Czechia was searched. Five suspects were interviewed in Spain and Latvia in the following days. At the end of the action week, the main perpetrator, suspected of being a developer of the Ragnar group, has been brought in front of the examining magistrates of the Paris Judicial Court.
The ransomware’s infrastructure was also seized in the Netherlands, Germany and Sweden and the associated data leak website on Tor was taken down in Sweden.
Ragnar Locker emerged in 2019 and quickly became known for its success in hacking organizations in various sectors, including health care, government, technology, finance, education, and media. It’s what’s known as a RAAS (ransomware as a service), in which core members develop the encryption software, run a central server, and then work with affiliates. The affiliates then hack victims, and profits are divided between the two groups. More about the group is available here and here.
Friday’s Europol post said Ragnar Locker members warned victims not to contact authorities because they would only “muck things up.”
In fact, Europol members, along with the FBI and Ukrainian authorities, had been investigating the group since 2021 and steadily made progress, culminating in this week’s arrest and takedown.
“Little did they know that law enforcement was closing in on them,” Europol said.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/10/two-ransomware-gangs-knocked-out-of-commission-in-a-single-week/