{"id":1213369,"date":"2023-12-19T12:47:55","date_gmt":"2023-12-19T17:47:55","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=1213369"},"modified":"2023-12-19T12:47:55","modified_gmt":"2023-12-19T17:47:55","slug":"the-doj-says-it-disrupted-the-blackcat-ransomware-group","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=1213369","title":{"rendered":"The DOJ says it disrupted the Blackcat ransomware group"},"content":{"rendered":"<p>The US Department of Justice <a data-i13n=\"elm:context_link;elmt:doNotAffiliate;cpos:1;pos:1\" class=\"no-affiliate-link\" href=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant\" data-original-link=\"https:\/\/www.justice.gov\/opa\/pr\/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant\">says<\/a> it has disrupted the Blackcat ransomware group. Also called ALPHV or Noberus, the hackers have targeted over 1,000 computer networks and extorted millions of dollars from victims. <em>Bloomberg<\/em> <a data-i13n=\"elm:context_link;elmt:doNotAffiliate;cpos:2;pos:1\" class=\"no-affiliate-link\" href=\"https:\/\/www.bloomberg.com\/news\/articles\/2023-12-19\/us-disrupts-blackcat-ransomware-gang-offering-decryption-tool\" data-original-link=\"https:\/\/www.bloomberg.com\/news\/articles\/2023-12-19\/us-disrupts-blackcat-ransomware-gang-offering-decryption-tool\">reports<\/a> its members were known for speaking Russian. \u201cIn disrupting the BlackCat ransomware group, the Justice Department has once again hacked the hackers,\u201d Deputy Attorney General Lisa O. Monaco wrote in a DOJ news release.<\/p>\n<p>The FBI says it developed a decryption tool, which it has used to help over 500 Blackcat victims recover their data \u2014\u00a0saving more than $68 million in ransom payments. The agency adds that it has \u201cgained visibility into the Blackcat ransomware group\u2019s computer network\u201d and seized several of its websites.<\/p>\n<p><span id=\"end-legacy-contents\" \/><\/p>\n<p>\u201cWith a decryption tool provided by the FBI to hundreds of ransomware victims worldwide, businesses and schools were able to reopen, and health care and emergency services were able to come back online,\u201d Monaco wrote. \u201cWe will continue to prioritize disruptions and place victims at the center of our strategy to dismantle the ecosystem fueling cybercrime.\u201d<\/p>\n<figure><img decoding=\"async\" src=\"\" data-crop-orig-src=\"https:\/\/s.yimg.com\/os\/creatr-uploaded-images\/2023-12\/5a7aff70-9e95-11ee-bbfb-52313c408106\" style=\"height:3128px;width:4511px\" alt=\"U.S. President Joe Biden listens as Deputy Attorney General Lisa Monaco speaks at an event announcing measures to fight ghost gun crime, at the White House, in Washington, U.S., April 11, 2022. REUTERS\/Kevin Lamarque\" data-uuid=\"132b213a-dbad-328b-959e-d9889d0c1d64\" \/><figcaption>US Deputy Attorney General Lisa O. Monaco with President Biden.<\/figcaption><div class=\"photo-credit\">REUTERS \/ Reuters<\/div>\n<\/figure>\n<p>Blackcat\u2019s developers create and update the ransomware software, which \u201caffiliates\u201d deploy in attacks on high-value targets; the developers and attackers then split the profits. Once an affiliate has infiltrated a network, they typically steal sensitive data before encrypting the victim\u2019s system, incapacitating it. They then ask for a ransom. If the victims pay, the hackers say they\u2019ll decrypt the system and abstain from exposing their confidential information. If the targets refuse to pony up, the hackers leave the victims locked out and publish their spicy documents on the dark web.<\/p>\n<p>Blackcat took credit for infiltrating businesses and other US and European organizations. These included hacks on <a data-i13n=\"cpos:3;pos:1\" href=\"https:\/\/www.engadget.com\/hackers-claim-it-only-took-a-10-minute-phone-call-to-shutdown-mgm-resorts-143147493.html\">MGM Resorts<\/a>, <a data-i13n=\"cpos:4;pos:1\" href=\"https:\/\/www.engadget.com\/caesars-reportedly-paid-millions-to-stop-hackers-releasing-its-data-081052820.html\">Caesars Entertainment<\/a>, <a data-i13n=\"cpos:5;pos:1\" href=\"https:\/\/www.engadget.com\/reddit-hackers-demand-45-million-and-api-changes-in-threat-to-leak-80gb-of-data-114041164.html\">Reddit<\/a>, US critical infrastructure (government facilities, emergency services, defense industrial base companies, critical manufacturing and healthcare facilities), a large UK hospital group and various attacks across the energy sector.<\/p>\n<p>Its members aren\u2019t afraid to think outside the box, either. Last month, Blackcat affiliates reportedly ratcheted the pressure on a hacked company by <a data-i13n=\"cpos:6;pos:1\" href=\"https:\/\/www.engadget.com\/hackers-use-a-new-sec-rule-to-snitch-on-the-company-they-infiltrated-201242292.html\">snitching to the SEC for not reporting their infiltration<\/a>.<\/p>\n<p>Although this could only be a fleeting upper hand in a long-running game of cat and mouse, the DOJ warns it\u2019s just getting started. \u201cCriminal actors should be aware that the announcement today is just one part of this ongoing effort,\u201d wrote the DOJ\u2019s Acting Assistant Attorney General Nicole M. Argentieri. \u201cGoing forward, we will continue our investigation and pursue those behind Blackcat until they are brought to justice.\u201d<\/p>\n<p>This article originally appeared on Engadget at https:\/\/www.engadget.com\/the-doj-says-it-disrupted-the-blackcat-ransomware-group-174755936.html?src=rss&#013;<br \/>\n&#013;<br \/>\nSource: Engadget &#8211; <a href=\"https:\/\/www.engadget.com\/the-doj-says-it-disrupted-the-blackcat-ransomware-group-174755936.html?src=rss\" target=\"_blank\" rel=\"noopener\">The DOJ says it disrupted the Blackcat ransomware group<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The US Department of Justice says it has disrupted the Blackcat ransomware group. Also called ALPHV or Noberus, the hackers have targeted over 1,000 computer networks and extorted millions of dollars from victims. Bloomberg reports its members were known for &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=1213369\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[99,110],"tags":[98],"class_list":["post-1213369","post","type-post","status-publish","format-standard","hentry","category-engadget","category-unfiltered-rss","tag-engadget"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1213369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1213369"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/1213369\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1213369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1213369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1213369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}