HomeSecurityFBI: Seizes $2.3 Million from REvil, Gandcrab Ransomware Affiliates

FBI: Seizes $2.3 Million from REvil, Gandcrab Ransomware Affiliates

The FBI seized $2.3 million in August from a known affiliate of REvil and the GandCrab ransomware.

FBI

See also: REvil ransomware: “Shuts down” again after breaching Tor sites

The agency seized 39.89138522 bitcoins worth approximately $2.3 million at current prices from an Exodus wallet on August 3, 2021.

Exodus is a desktop or mobile wallet that owners can use to store cryptocurrencies, including Bitcoin, Ethereum, Solana, and many others.

The FBI did not reveal how they gained access to the wallet, other than that it was now in their hands, indicating that they likely gained access to the wallet's private key or password.

The United States of America files this verified material complaint against 39.89138522 Bitcoin seized from Exodus Wallet, now in the custody and management of the Federal Bureau of Investigation (“FBI”) Dallas Division, One Justice Way, Dallas Texas,” the complaint .

The complaint goes on to say that the wallet contained REvil ransom payments belonging to an affiliate identified as “Aleksandr Sikerin, a/k/a Alexander Sikerin, a/k/a Oleksandr Sikerin” with an email address of “engfog1337@gmail.com.”

See also: FBI: Warns of brand phishing targeting high-profile customers

While the FBI does not indicate the online alias of the malicious actor, the name “engfog” in the email address is linked to a known affiliate of GandCrab and REvil/Sodinokibi known as “Lalartu.”

The GandCrab and REvil organizations operated as Ransomware-as-a-Service (RaaS), where the key operators collaborate with third-party hackers, known as collaborators.

As part of this agreement, the main operators develop and manage the encryption/decryption software, payment gateway and data leakage sites. The subsidiaries are tasked with hacking corporate networks, stealing data and developing ransomware to encrypt devices.

REvil GandCrab

Any ransom payments will then be split between the affiliates and the main operators, with the operators generally earning 20-30% of the ransom and the affiliates making the rest.

As part of his investigation, security researcher Alon Gal tracked Lalartu under the alias “Engfog” or “Eng_Fog,” which matches the email address “engfog1337@gmail.com” listed in the FBI complaint.

In November, the Department of Justice announced that the FBI had seized $6 million in ransom money paid to the REvil ransomware gang.

It is unclear whether this $2.3 million is part of the previously announced figure or additional ransom money seized by the FBI.

See also: USA: $10 million reward for REvil leaders

Law enforcement's ongoing strategy to disrupt the financial and subsidiary systems of ransomware operations is paying off.

This activity has led to numerous arrests and the dismantling of infrastructure, such as:

  • The disruption of Netwalker's ransomware operation and the arrest of a subsidiary in Canada.
  • The arrest of the two members of the Egregor operation led to the closure of the organization.
  • The arrest of 12 people believed to be linked to ransomware attacks against 1,800 victims in 71 countries.
  • The arrest of a Ukrainian national believed to be behind the Kaseya ransomware attack.

Arrests and infrastructure seizures are scaring ransomware gangs into shutting down their operations, including REvil in October and BlackMatter in July.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS