Says It Shut Down Notorious Hacker Group at U.S. Request

[wsj.com] The Russian government on Friday said it had arrested members of the prolific criminal ransomware group known as REvil that has been blamed for major attacks against U.S. business and critical infrastructure, disrupting its operations at the request of U.S. authorities.

Russia’s security service, the FSB, said in an online press release that it had halted REvil’s “illegal activities” and seized funds belonging to the group from more than two dozen residences in Moscow, St. Petersburg and elsewhere. REvil members were arrested in relation to money-laundering charges, the FSB said. It didn’t provide names of any of the suspects.

The arrests included “the individual responsible for the attack on Colonial Pipeline last spring,” a particularly devastating ransomware offensive that led to the main conduit of fuel on the U.S. East Coast being shut down for days, a senior Biden administration official said. A different Russian ransomware gang had previously been linked to the Colonial hack, but security experts and officials have said they are not neatly defined and that individual hackers often overlap.

“We welcome reports the Kremlin is taking law enforcement steps to address ransomware within its borders,” the official said.

TASS, the Russian state news agency, said 14 members of REvil had been arrested. A Russian government video published online by TASS Friday showed clips of Russian law enforcement forcibly entering apartments, detaining suspects whose faces are blurred out, and counting large bundles of Russian and American currency. TASS identified one of the people arrested as Roman Muromsky.

Analysts said the timing of the action was notable because it arrived alongside rising tensions between Russia and Ukraine, as U.S. and NATO efforts so far to ease the situation appear to have faltered.

“This is Russian ransomware diplomacy,” said Dmitri Alperovitch, chairman of the Silverado Policy Accelerator, a Washington-based cybersecurity think tank. “It is a signal to the United States—if you don’t enact severe sanctions against us for invasion of Ukraine, we will continue to cooperate with you on ransomware investigations.”

The senior administration official said the crackdown on Friday “is not related to what’s happening with Russia and Ukraine,” and that the U.S. has been clear what penalties Moscow will face if it invades its neighbor.

The Russian Embassy in Washington declined to comment and only referred back to the FSB press release.

The operation against REvil would amount to the most significant action Russia has taken against ransomware gangs that operate within its borders. The group is one of the most notorious ransomware gangs in Russia and was blamed for major attacks last year in the U.S. that disrupted operations at a major meat supplier, for which it netted a ransom payment of $11 million, and another attack that affected about 1,500 businesses.

U.S. officials have long accused Russia of claiming to prosecute hackers and other criminals that they later release and enlist to help in their government cyber operations.

While the arrest of 14 alleged ransomware hackers seems like a significant breakthrough in diplomatic relations, it may merely be intended as a gesture by Russia to placate the U.S. ahead of possible Ukraine-related sanctions, said Gary Warner, director of threat intelligence with the cybersecurity firm DarkTower. “It probably does not mean that a new era of cybercrime cooperation has opened.”

Russia ceased cooperation with U.S. authorities on investigations about eight years ago, around the time of Russia’s annexation of Crimea and U.S. sanctions that resulted, he said.

President Biden last year identified ransomware attacks emanating from Russia to be a top national security threat, and he has repeatedly pressured Russian President Vladimir Putin to crack down on criminal ransomware groups. Ransomware is a type of malicious cyberattack that locks up a computer system and holds data until the victim pays a ransom, typically in cryptocurrency.

Since last summer, U.S. and Russian officials have held several bilateral conversations to discuss the issue. Some of those conversations included the U.S. sharing specific names and intelligence with Russia about hackers identified as ransomware operators, officials familiar with the conversations have previously said.

U.S. officials have offered at times mixed messages about whether Russian ransomware attacks have fallen as a result of the administration’s diplomatic efforts, but until now there has been little public evidence that Moscow was cooperating.

The announcement of the crackdown came amid a growing buildup of Russian troops and military equipment at its border with Ukraine, as the U.S. and western allies have tried unsuccessfully to ease tensions between the neighbors. Ukraine also said Friday it had been hit by a cyberattack that had knocked several of its government websites offline. It wasn’t clear who was responsible.

Written By Obioma Ezenwobodo Esq

The three are Law and Practice of Court Martial In Nigeria (N8000 per copy), Handbook on Court Martial Practice (N6000 per copy), and Fundamentals of Confessional Statement in Criminal Trials (N7, 000 per copy).

ORDER: Call or SMS the Publisher 08064999866 or email:lawcraftpublishersltd@gmail.com. You can also contact: Abuja - Alex 08035991379, Lagos - Yetmoris 08033855230, Enugu - Helen 07067176508, Port Harcourt - Bukky 08034868754, Jos - Bidemi 0806 446 5858, Kano - Raphael 08034010013