US infiltrates big ransomware gang: ‘We hacked the hackers’

26 January 2023, 20:24

US deputy attorney general Lisa Monaco, flanked by attorney general Merrick Garland, left, and FBI director Christopher Wray, speaks during a news conference to announce an international ransomware en
Ransomware Justice Department. Picture: PA

Officials said the targeted syndicate, known as Hive, operates one of the world’s top five ransomware networks.

The FBI and international partners have at least temporarily dismantled the network of a prolific ransomware gang they infiltrated last year, saving victims including hospitals and school districts a potential 130 million dollars (£105 million) in ransom payments, US officials announced.

“Simply put, using lawful means we hacked the hackers,” deputy attorney general Lisa Monaco said at a news conference.

Officials said the targeted syndicate, known as Hive, operates one of the world’s top five ransomware networks and has heavily targeted hospitals and other healthcare providers.

The FBI quietly gained access to its control panel in July and was able to obtain software keys to decrypt the network of some 1,300 victims globally, said FBI director Christopher Wray.

FBI director Christopher Wray speaks during a news conference to announce an international ransomware enforcement action, at the Department of Justice in Washington
FBI director Christopher Wray speaks during a news conference at the Department of Justice in Washington (Jose Luis Magana/AP)

Officials credited German police and other international partners.

It was not immediately clear how the takedown will affect Hive’s long-term operations, however.

Officials did not announce any arrests but said they were building a map of Hive’s administrators, who manage the software, and affiliates, who infect targets and negotiate with victims, to pursue prosecutions.

“I think anyone involved with Hive should be concerned because this investigation is ongoing,” Mr Wray said.

On Wednesday night, FBI agents seized computer infrastructure in Los Angeles that was used to support the network.

Two Hive dark web sites were seized: one used for leaking data of non-paying victims, the other for negotiating extortion payments.

“Cybercrime is a constantly evolving threat, but as I have said before, the Justice Department will spare no resource to bring to justice anyone anywhere that targets the United States with a ransomware attack,” Mr Garland said.

US attorney general Merrick Garland said that thanks to the infiltration, led by the FBI’s Tampa office, agents were able in one instance to disrupt a Hive attack against a Texas school district, stopping it from making a five million dollar (£4 million) payment.

Attorney General Merrick Garland speaks during a news conference to announce an international ransomware enforcement action, at the Department of Justice in Washington
Attorney general Merrick Garland speaks during a news conference at the Department of Justice in Washington (Jose Luis Magana/AP)

The operation is a big win for the Justice Department.

The ransomware scourge is the world’s biggest cybercrime headache, with everything from Britain’s postal service and Ireland’s national health service to Costa Rica’s government crippled by Russian-speaking syndicates that enjoy Kremlin protection.

The criminals lock up, or encrypt, victims’ computer networks, steal sensitive data and demand large sums.

As an example of Hive’s threat, Mr Garland said it had prevented a hospital in the Midwest in 2021 from accepting new patients at the height of the Covid-19 epidemic.

The online takedown notice, alternating in English and Russian, mentions Europol and German federal and state police as partners in the effort.

The German news agency dpa quoted the public prosecutor’s office in Stuttgart as saying cyber specialists in the south-western town of Esslingen were decisive in penetrating Hive’s criminal IT infrastructure after a local company was victimised.

In a statement, Europol said companies in more than 80 countries, including oil multinationals, have been compromised by Hive.

It said Europol assisted with cryptocurrency, malware and other analysis, and that law enforcement agencies from 13 countries were involved in the effort.

The Department of Justice seal is seen before a news conference to announce an international ransomware enforcement action at the Department of Justice in Washington
The Department of Justice seal (Jose Luis Magana/AP)

A US government advisory last year said Hive ransomware actors victimised more than 1,300 companies worldwide from June 2021 through to November 2022, receiving approximately 100 million dollars (£80 million) in ransom payments.

It said criminals using Hive ransomware targeted a wide range of businesses and critical infrastructure, including government, manufacturing and especially healthcare and public health facilities.

The threat captured the attention of the highest levels of the Biden administration two years ago after a series of high-profile attacks that threatened critical infrastructure and global industry.

In May 2021, for instance, hackers targeted the nation’s largest fuel pipeline, causing the operators to briefly shut it down and make a multimillion-dollar ransom payment that the US government largely recovered.

Federal officials have used a variety of tools to try to combat the problem, but conventional law enforcement measures such as arrests and prosecutions have done little to frustrate the criminals.

The FBI has obtained access to decryption keys before.

It did so in the case of a major 2021 ransomware attack on Kaseya, a company whose software runs hundreds of websites.

It took some heat, however, for waiting several weeks to help victims unlock afflicted networks.

By Press Association

More Technology News

See more More Technology News

Hands on a laptop

Estimated 7m UK adults own cryptoassets, says FCA

A teenager uses his mobile phone to access social media,

Social media users ‘won’t be forced to share personal details after child ban’

Google Antitrust Remedies

US regulators seek to break up Google and force Chrome sale

Jim Chalmers gestures

Australian government rejects Musk’s claim it plans to control internet access

Graphs showing outages across Microsoft

Microsoft outage hits Teams and Outlook users

The Google logon on the screen of a smartphone

Google faces £7 billion legal claim over search engine advertising

A person holds an iphone showing the app for Google chrome search engine

Apple and Google ‘should face investigation over mobile browser duopoly’

UK unveils AI cyber defence lab to combat Russian threats, as minister pledges unwavering support for Ukraine

British spies to ramp up fight against Russian cyber threats with launch of cutting-edge AI research unit

Pat McFadden

UK spies to counter Russian cyber warfare threat with new AI security lab

Openreach van

Upgrade to Openreach ultrafast full fibre broadband ‘could deliver £66bn boost’

Laptop with a virus warning on the screen

Nato countries are in a ‘hidden cyber war’ with Russia, says Liz Kendall

Pat McFadden

Russia prepared to launch cyber attacks on UK, minister to warn

A Google icon on a smartphone

Firms can use AI to help offset Budget tax hikes, says Google UK boss

Icons of social media apps, including Facebook, Instagram, YouTube and WhatsApp, are displayed on a mobile phone screen

Growing social media app vows to shake up ‘toxic’ status quo

Will Guyatt questions who is responsible for the safety of children online

Are Zuckerberg and Musk responsible for looking after my kids online?

Social media apps on a phone

U16s social media ban punishes children for tech firm failures, charities say