Pipeline Ransom Has Been Paid

The Colonial Pipeline company has paid $5 million to the DarkSide, a criminal hacking group, to restore operations after a ransomware attack paralysed fuel supplies across the US eastern seaboard. 

DarkSide are the suspected Russian-based group that the FBI has said was responsible for the attack, has told its affiliates it is 'closing its services', according  to FireEye, the leading cyber security group appointed to investigate the incident. 

Experts are warning that ransomware attacks, which are partly ransom, partly blackmail, are becoming more frequent, as the often Russia-based hackers are becoming more sophisticated with their hacking cyber attacks which have hit power generation, federal and local government agencies, water treatment plants and even police departments across the US.

Hit by a cyber attack, the operator of a major US fuel pipeline was forced to shut down service that is currently causing gas shortages throughout the Southeast. And the US sanctioned the Kremlin recently for a hack of federal government agencies, known as the SolarWinds breach, that officials have linked to a Russian intelligence unit and characterised as an intelligence-gathering operation.

As the US was focused on the pipeline attack, another hacker group hit the Washington DC Metro Police.  A day after US President Joe Biden said the US plans to disrupt the hackers behind the Colonial Pipeline cyber attack, the operator of the Darkside ransomware said the group lost control of its web servers and some of the funds it made from ransom payments. “A few hours ago, we lost access to the public part of our infrastructure, namely: Blog. Payment server. CDN servers,” said Darksupp, the operator of the Darkside ransomware in a post.  “Now these servers are unavailable via SSH, and the hosting panels are blocked,” said the Darkside operator while also complaining that the web hosting provider refused to cooperate.

In addition, the Darkside operator also reported that crypto currency funds were also withdrawn from the gang’s payment server, which was hosting ransom payments made by victims. 

The funds, which the Darkside gang was supposed to split between itself and its affiliates were transferred to an unknown wallet, Darksupp said.

Background

One of the first known cases involving Darkside ransomware occurred in late August 2020. The victim was a Canadian construction firm, which  refused to pay the ransom and instead restored their data and systems from backups.  Another company, hit with the Darkside ransomware around the same time, did pay the ransom, $2 million. The Darkside ransomware locked about 5,000 of the company’s computers and servers, including data backups that they’d kept online. According to Stephen Boyce, a former FBI investigator then working for the US security company Crypsis who led the team that investigated the infection. “Our victim paid, so they were not publicly named and/or shamed,” The the victim was a privately held US-based holding company, which Boyce declined to name.   

FireEye has published a detailed timeline of DarkSide’s movements, revealing that threat actors have “become more proficient at conducting multifaceted extortion operations”, adding that this success has “directly contributed to the rapid increase in the number of high-impact ransomware incidents over the past few years”.and they expect to see varying extortion techniques leveraging DarkSide malware that “will continue to evolve throughout 2021”.

Biden Orders Better Cyber Defence

President  Biden has now signed an Executive Order to improve US cyber defences in light of recent attack meant to strengthen US cybersecurity defences in response to a series of headline-grabbing hacking incidents that highlight how vulnerable the country''s public and private sectors are to high-tech spies and criminals operating from half a world away. Since December, the US has been on the receiving end of three of the worst cyber-attacks in history, each one different, as if testing the administration in different ways.

The order comes as the administration has been grappling with its response to a massive breach by Russia of federal agencies and ransomware attacks on private corporations.

The detailed order issues strict deadlines for all government departments to tighten security. It comes as the US deals with a hack on the country's biggest pipeline that has seen fuel shortages and panic-buying across multiple states. Colonial Pipeline says it has restarted its pumps but it will be "several days" until fuel supplies return to normal.

FireEye:    Recorded Future:     Guardian:     Zero Day:   Portswigger:     

 Bloomberg:      BBC:     DTNext:    TEISS:     Image: Unsplash

You Might Also Read:

Running Out Of Cyber Gas:

 

« Stop Taking Risks Online
The Next E-Industrial Revolution »

Quartz Conference
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / Zero Trust Network Access Guide

Perimeter 81 / Zero Trust Network Access Guide

Curious how you can Implement a Zero Trust roadmap with insights from Gartner? Download this free report for a limited time only.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Clayden Law

Clayden Law

Clayden Law are experts in information technology, data privacy and cybersecurity law.

Imperva

Imperva

Imperva is a leading provider of data and application security solutions including DDoS protection, Web application security, Data security and Cloud security.

Vanguard Integrity Professionals

Vanguard Integrity Professionals

Vanguard Integrity Professionals is an independent provider of enterprise security software solutions that address complex security and regulatory compliance challenges.

National Cyber Security Centre (NCSC) - United Kingdom

National Cyber Security Centre (NCSC) - United Kingdom

The NCSC acts as a bridge between industry and government, providing a unified source of advice, guidance and support on cyber security, including the management of cyber security incidents.

Chubb

Chubb

Chubb is the world’s largest publicly traded property and casualty insurer. Commercial services include Cyber Risk insurance.

Intertek Group

Intertek Group

Intertek Group provides Assurance, Testing, Inspection and Certification services. Activities include cybersecurity testing and certification.

cPacket Networks

cPacket Networks

cPacket’s distributed intelligence enables network operators to proactively identify imminent issues before they negatively impact end-users.

RATEL (SRB-CERT)

RATEL (SRB-CERT)

RATEL has been appointed as the National Center for the Prevention of Security Risks in ICT systems of the Republic of Serbia (SRB-CERT).

Samoby

Samoby

Samoby provide a subscription solution for Mobile Threat Protection and usage control on Android and iOS devices.

Veracity Industrial Networks

Veracity Industrial Networks

Veracity provides an innovative industrial network platform that improves the reliability, efficiency, and security of industrial networks and devices.

RackTop Systems

RackTop Systems

RackTop Systems is the pioneer of CyberConverged data security, a new market that fuses data storage with advanced security and compliance into a single platform.

Echosec Systems

Echosec Systems

Echosec Systems is a data discovery company delivering social media and dark web threat intelligence. Our web based security software delivers critical information for situational awareness.

Liongard

Liongard

Liongard automates the management and protection of modern IT environments at scale for IT MSPs - Managed Service Providers and Enterprise IT Operations.

PPC Protect

PPC Protect

PPC Protect is an entirely automated click fraud prevention solution.

Thistle Technologies

Thistle Technologies

Thistle Technologies is building tools that help connected device manufacturers build security resiliency into devices.

Digitale Gründerinitiative Oberpfalz (DGO)

Digitale Gründerinitiative Oberpfalz (DGO)

Digital Founder Initiative Oberpfalz's goal is to build a sustainable start-up culture in the field of digitization throughout the Upper Palatinate district of Bavaria.

Stryve

Stryve

Stryve is a leading carbon-neutral provider of specialist cloud and cybersecurity services in Europe.