HomeSecurityALPHV/BlackCat ransomware: Recent outage may be due to a "hit" by...

ALPHV/BlackCat ransomware: Recent outage may be due to a “strike” by authorities

A law enforcement operation may be behind an outage that affected the websites of the ALPHV/BlackCat ransomware gang.

ALPHV/BlackCat ransomware

The gang's trading and data- leaking websites suddenly became unavailable last Thursday.

BleepingComputer also confirmed that the unique Tor URLs shared with victims for ransom were also down.

When asked about the outage on Thursday, the Administrator of the ALPHV ransomware told BleepingComputer that the sites may be back online soon.

BleepingComputer suspects that the ransomware gang has been “attacked by law enforcement following its recent attacks on large organizations.

See also: HTC Global Services: Is ALPHV/BlackCat ransomware behind the attack?

There are wild (and loud) rumors that ALPHV/Blackcat received a visit from the FBI,” reads a tweet from someone named Evangelos G.

On Friday afternoon, cybersecurity firm RedSense Intel also confirmed to BleepingComputer that the servers were shut down due to law enforcement action. The company also announced the news via a tweet onX.

There has been no official announcement from the FBI about the ALPHV/BlackCat ransomware gang's servers being compromised. However, similar outages have been observed in the past by other criminal gangs that have been targeted by authorities. For example, when the FBI breached the REvil, they obtained the decryption keys for the victims of the Kaseya.

The FBI has also breached the infrastructure of the Hive ransomware, secretly obtaining decryption keys and distributing them to victims.

ALPHV/BlackCat ransomware: Recent outage may be due to a "strike" by authorities

ALPHV/BlackCat ransomware

The ALPHV/BlackCat ransomware operation is believed to be gang DarkSide. It began operations in 2020 and quickly rose to prominence. However, after the attack on the Colonial Pipeline, it faced intense scrutiny from the US government and law enforcement, which ultimately led to the seizure of its infrastructure and the termination of the operation.

See also: Tipalti: Investigates allegations of BlackCat ransomware gang breach

Just a few months later, the ransomware gang returned under the name BlackMatter. However, the hackers had said they were affiliates of the DarkSide operation and not the original leaders.

Four months later, BlackMatter shut down after claiming it was under pressure from law enforcement.

In February 2022, ALPHV/BlackCat ransomware appeared.

ALPHV/BlackCat ransomware: Recent outage may be due to a "strike" by authorities

Ransomware protection

One of the main methods of protection against the ALPHV/BlackCat ransomware cyber threat is awareness and education user. It is important for users to be aware of the latest threats and know how to recognize malicious emails, unsafe links, and other situations that may expose their system to risks.

Another way to protect yourself is to use up-to-date and reliable security software. Users should install a reliable antivirus and firewall, and update them regularly to detect and block any malware.

See also: LockBit: Still the most serious ransomware threat

Additionally, regular backups are crucial. If users keep copies of their files on external drives or secure storage, they can recover data even if they fall victim to ransomware.

Finally, careful web browsing is essential to protect against ALPHV/BlackCat ransomware. Users should avoid visiting suspicious websites, avoid clicking on pop-ups, and be careful about downloading files from untrusted sources.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS