Jump to content
Check your account email address ×

Darkside ransomware gang says it lost control of its servers & money a day after Biden threat


Recommended Posts

President Biden a real leader on the job…..

Darkside ransomware gang says it lost control of its servers & money a day after Biden threat
 

A day after US President Joe Biden said the US plans to disrupt the hackers behind the Colonial Pipeline cyberattack, the operator of the Darkside ransomware said the group lost control of its web servers and some of the funds it made from ransom payments. 

“A few hours ago, we lost access to the public part of our infrastructure, namely: Blog. Payment server. CDN servers,” said Darksupp, the operator of the Darkside ransomware, in a post spotted by Recorded Future threat intelligence analyst Dmitry Smilyanets. “Now these servers are unavailable via SSH, and the hosting panels are blocked,” said the Darkside operator while also complaining that the web hosting provider refused to cooperate. 

In addition, the Darkside operator also reported that cryptocurrency funds were also withdrawn from the gang’s payment server, which was hosting ransom payments made by victims. The funds, which the Darkside gang was supposed to split between itself and its affiliates (the threat actors who breach networks and deploy the ransomware), were transferred to an unknown wallet, Darksupp said. 

This sudden development comes after US authorities announced their intention to go after the gang.

Read more: https://therecord.media/darkside-ransomware-gang-says-it-lost-control-of-its-servers-money-a-day-after-biden-threat/ 

Link to comment
Share on other sites

Happy to have additional attention on my line of business. The last three presidents have all pushed cybersecurity investment. It's important stuff. For every one of these events that happens, tens of thousands are thwarted. 

  • Like 2
Link to comment
Share on other sites

5 hours ago, Mainecat said:

President Biden a real leader on the job…..

Darkside ransomware gang says it lost control of its servers & money a day after Biden threat
 

A day after US President Joe Biden said the US plans to disrupt the hackers behind the Colonial Pipeline cyberattack, the operator of the Darkside ransomware said the group lost control of its web servers and some of the funds it made from ransom payments. 

“A few hours ago, we lost access to the public part of our infrastructure, namely: Blog. Payment server. CDN servers,” said Darksupp, the operator of the Darkside ransomware, in a post spotted by Recorded Future threat intelligence analyst Dmitry Smilyanets. “Now these servers are unavailable via SSH, and the hosting panels are blocked,” said the Darkside operator while also complaining that the web hosting provider refused to cooperate. 

In addition, the Darkside operator also reported that cryptocurrency funds were also withdrawn from the gang’s payment server, which was hosting ransom payments made by victims. The funds, which the Darkside gang was supposed to split between itself and its affiliates (the threat actors who breach networks and deploy the ransomware), were transferred to an unknown wallet, Darksupp said. 

This sudden development comes after US authorities announced their intention to go after the gang.

Read more: https://therecord.media/darkside-ransomware-gang-says-it-lost-control-of-its-servers-money-a-day-after-biden-threat/ 

Incase you are curious this is what propaganda looks like 

Link to comment
Share on other sites

Cool.  Like Trump wouldn't have done the same thing.  Or prevented it from happening in the first pla

19 hours ago, Mainecat said:

President Biden a real leader on the job…..

Darkside ransomware gang says it lost control of its servers & money a day after Biden threat
 

A day after US President Joe Biden said the US plans to disrupt the hackers behind the Colonial Pipeline cyberattack, the operator of the Darkside ransomware said the group lost control of its web servers and some of the funds it made from ransom payments. 

“A few hours ago, we lost access to the public part of our infrastructure, namely: Blog. Payment server. CDN servers,” said Darksupp, the operator of the Darkside ransomware, in a post spotted by Recorded Future threat intelligence analyst Dmitry Smilyanets. “Now these servers are unavailable via SSH, and the hosting panels are blocked,” said the Darkside operator while also complaining that the web hosting provider refused to cooperate. 

In addition, the Darkside operator also reported that cryptocurrency funds were also withdrawn from the gang’s payment server, which was hosting ransom payments made by victims. The funds, which the Darkside gang was supposed to split between itself and its affiliates (the threat actors who breach networks and deploy the ransomware), were transferred to an unknown wallet, Darksupp said. 

This sudden development comes after US authorities announced their intention to go after the gang.

Read more: https://therecord.media/darkside-ransomware-gang-says-it-lost-control-of-its-servers-money-a-day-after-biden-threat/ 

Great news.  Biden still fucking blows.

Link to comment
Share on other sites

  • Gold Member
5 minutes ago, Jimmy Snacks said:

Glad the pipeline is back online but shouldn’t  the company be responsible for their own cyber security?
 

Not as long a democrat is in office...

Link to comment
Share on other sites

  • Gold Member
14 minutes ago, Jimmy Snacks said:

Glad the pipeline is back online but shouldn’t  the company be responsible for their own cyber security?
 

I dunno, I seem to remember the trump admin being blamed for the infected security update that got sent to like 18,000 companies by 1 company. 

Link to comment
Share on other sites

  • Platinum Contributing Member
18 minutes ago, Kivalo said:

Not as long a democrat is in office...

Generally Republicans are against over regulation and government sticking their nose into private businesses but yeah this was Sleepy Joe’s fault. 😂

7 minutes ago, Stephen Hawking said:

I dunno, I seem to remember the trump admin being blamed for the infected security update that got sent to like 18,000 companies by 1 company. 

I don’t recall that but if a private company fucks up it’s on them. 

Edited by Jimmy Snacks
Link to comment
Share on other sites

4 hours ago, DriftBusta said:

Cool.  Like Trump wouldn't have done the same thing.  Or prevented it from happening in the first pla

Great news.  Biden still fucking blows.

Like in December 2020?

Link to comment
Share on other sites

1 hour ago, Jimmy Snacks said:

Glad the pipeline is back online but shouldn’t  the company be responsible for their own cyber security?
 

Yes, but industries like this (can put the country on it's knees) the gov't should be checking in on them and helping (read: helping) develop new/better security.

Edit in: I don't feel there is blame on any admin for this. My opinion, again, is there should be help from our national cyber securities and such.

Edited by CFM
Link to comment
Share on other sites

  • Platinum Contributing Member
2 hours ago, Jimmy Snacks said:

Glad the pipeline is back online but shouldn’t  the company be responsible for their own cyber security?
 

For the most part yes but attacks against infrastructure are a bit different than hacking Sony executive files.

Link to comment
Share on other sites

When your business is hacked and there is ransomware your required to inform the government. We were hacked and bitcoin was required by the hackers so we called the local police, they told us to call the state police and they told us we had to call the government. It’s a national security issue.

Edited by Mainecat
Link to comment
Share on other sites

Companies are responsible for their own security infrastructure but often times they are hamstrung by their vendors. This is especially true in the medical device field (scary). 

Example: you are a hospital and buy an MRI from GE. That MRI comes with management/control software with a bundled version of Windows 2012 or 2016 server (already outdated). Since the control software that runs on top of the OS has OS dependencies, GE says you will void your support contract if you patch the server OS. OS vulnerabilities are the cause of the vast majority of breach events. 

It's not just GE. But next time you are having imaging done, take a look at the console if you're able to. Bet it's running outdated Windows. 

  • Confused 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Trying to pay the bills, lol



×
×
  • Create New...