REvil returns, but under another name
Or is it?
When you purchase through links on our site, we may earn an affiliate commission.Here’s how it works.
The emergence of a new threat actor in underground forums has ledcybersecurityexperts to speculate the outfit could perhaps just be REvilransomwareoperator under a changed name.
Earlier this month, the notoriousRussia-basedransomware grouptook all its online properties offline, leading to speculation that the group could have been hit by law enforcement agencies, following its extravagant attack against managed service providers (MSP) by exploiting a vulnerability in the Kaseya VSAremotemanagement software toinfect thousands of computersaround the world.
Identifying themselves as BlackMatter, the new threat actor has expressed interest in purchasing access to compromised corporate networks in the US, UK, Canada, and Australia.
We’re looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won’t take more than 60 seconds of your time, and we’d hugely appreciate if you’d share your experiences with us.
Click here to start the survey in a new window«
Analysts at risk intelligence firm Flashpoint havedrawn several similaritiesbetween BlackMatter and REvil regarding their tactics and policy of staying clear of medical and government institutions.
No smoking gun
After registering on the Russian-language hacker forums, XSS and Exploit, BlackMatter made a substantial deposit of fourbitcoin(about $150,000) in an escrow account, before posting its request looking for targets.
The seriousness of BlackMatter’s intent is what brought the group immediately to the attention of observers.
However, the Flashpoint researchers note that the new group could just be copycats imitating REvil’s behavior to gain immediate credibility as its reincarnation.
Are you a pro? Subscribe to our newsletter
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Furthermore, while the language of their post, and their goals clearly point to the fact that BlackMatter is a ransomware operator, the researchers suggest that one shouldn’t jump to conclusion just yet since “two posts and a large escrow account do not make a ransomware group.”
With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’sTechRadar Pro’sexpert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.
This new malware utilizes a rare programming language to evade traditional detection methods
A new form of macOS malware is being used by devious North Korean hackers
I’ve been covering Apple Watch deals for years – This is the one model most people should buy on Black Friday