The West News
    Facebook Twitter Instagram
    The West News
    • Home
    • News
      • Tech
      • Sports
      • Local
    • Entertainment
    • Gaming
      • Guides
      • Elden Ring
      • Fortnite
      • New World
      • FIFA 22
      • Pokemon Go
    • Credit Card
    Facebook Twitter Instagram
    The West News
    Home»News»After Tor sites were compromised, the REvil Ransomware Gang went underground
    News

    After Tor sites were compromised, the REvil Ransomware Gang went underground

    The West NewsBy The West NewsOctober 18, 2021Updated:October 18, 20212 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    REvil Ransomware Gang Goes Underground
    Share
    Facebook Twitter LinkedIn Pinterest Email

    After Tor sites were compromised, the REvil Ransomware Gang went underground

    REvil, the notorious ransomware gang responsible for a slew of cyberattacks in recent years, appears to have vanished once more, just over a month after the cybercrime group made a shocking return after a two-month sabbatical.

    The discovery was made by Dmitry Smilyanets of Recorded Future when a member of the REvil organisation wrote on the XSS hacking forum that anonymous actors had taken control of the gang’s Tor payment gateway and data leak website.

    “The server was compromised and they were looking for me. To be precise, they deleted the path to my hidden service in the torrc file and raised their own so that I would (sic) go there. I checked on others – this was not. Good luck everyone, I’m off,” user 0_neday said in the post.

    As of this writing, it is unclear who was responsible for the hack of REvil’s servers, though it wouldn’t be shocking if government enforcement authorities played a role in pulling the domains down.

    Following its attacks on JBS and Kaseya earlier this year, the Russia-linked ransomware organisation was forced to shut down its darknet domains in July 2021. However, on September 9, 2021, REvil made a surprising comeback, reactivating both its data leak site as well as its payment and negotiating sites.

    The Washington Post revealed last month that the FBI withheld for nearly three weeks from sharing the decryptor with victims of the Kaseya ransomware attack, which it obtained by accessing the group’s servers, as part of a scheme to disrupt the gang’s harmful actions. “The planned takedown never occurred because in mid-July REvil’s platform went offline — without U.S. government intervention — and the hackers disappeared before the FBI had a chance to execute its plan,” the report added.

    After collecting the digital key from a “law enforcement partner,” Romanian cybersecurity firm Bitdefender eventually shared a universal decryptor in late July.

    While it is common for ransomware groups to evolve, splinter, or reorganise under new names, the criminal field has increasingly come under scrutiny for targeting critical infrastructure, even as more cybercriminals recognise the profitability of ransomware, which is aided in part by the unregulated cryptocurrency landscape, allowing threat actors to extort victims for digital payments with impunity.

    News Tech
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The West News
    • Website

    TheWestNews is a publication where we share the latest news regarding entertainment, gaming, sports, and local American news. Want to be featured or have some tip for us then reach at "[email protected]"

    Related Posts

    $20 Million Jackpot – Mega Millions winning numbers for February 3 2023

    February 4, 2023

    How this Ferrari Roma ended up in an elevator

    February 4, 2023

    Apple’s Crash Detection is still troubling emergency services

    February 4, 2023

    Comments are closed.

    $20 Million Jackpot – Mega Millions winning numbers for February 3 2023

    February 4, 2023

    How this Ferrari Roma ended up in an elevator

    February 4, 2023

    Apple’s Crash Detection is still troubling emergency services

    February 4, 2023

    Netflix claims it accidentally published strict password sharing guidelines

    February 4, 2023
    Facebook Twitter Instagram Pinterest
    • About Us
    • Contact
    • Disclaimer
    • Privacy Policy
    • Sitemap
    © 2023 TheWestNews.

    Type above and press Enter to search. Press Esc to cancel.