CIO News Hubb
Advertisement
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact
No Result
View All Result
CIO News Hubb
No Result
View All Result
Home Information Security

Gold Ulrick Hackers Still in Action Despite Massive Conti Ransomware Leak

admin by admin
April 26, 2022
in Information Security
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter


The infamous ransomware group known as Conti has continued its onslaught against entities despite suffering a massive data leak of its own earlier this year, according to new research.

Conti, attributed to a Russia-based threat actor known as Gold Ulrick, is one of the most prevalent malware strains in the ransomware landscape, accounting for 19% of all attacks during the three-month-period between October and December 2021.

One of the most prolific ransomware groups of the last year along the likes of LockBit 2.0, PYSA, and Hive, Conti has locked the networks of hospitals, businesses, and government agencies, while receiving a ransom payment in exchange for sharing the decryption key as part of its name-and-shame scheme.

But after the cybercriminal cartel came out in support of Russia over its invasion of Ukraine in February, an anonymous Ukrainian security researcher under the Twitter handle ContiLeaks began leaking the source code as well as private conversations between its members, offering an unprecedented insight into the group’s workings.

CyberSecurity

“The chats reveal a mature cybercrime ecosystem across multiple threat groups with frequent collaboration and support,” Secureworks said in a report published in March. The groups include Gold Blackburn (TrickBot and Diavol), Gold Crestwood (Emotet), Gold Mystic (LockBit), and Gold Swathmore (IcedID).

Indeed, Intel 471’s technical monitoring of Emotet campaigns between December 25, 2021, and March 25, 2022, identified that over a dozen Conti ransomware targets were, in fact, victims of Emotet malspam attacks, highlighting how the two operations are intertwined.

That said, the leaks don’t seem to have put a dampener on the syndicate’s activities, with the number of Conti victims posted in March surging to the second-highest monthly total since January 2021, per the Atlanta-headquartered cybersecurity firm.

What’s more, the group is said to have added 11 victims in the first four days of April, even as the operators continue to “evolve its ransomware, intrusion methods, and approaches” in response to the public disclosure of their arsenal.

The findings have also been corroborated by NCC Group late last month, which said that “Conti operators continue their business as usual by proceeding to compromise networks, exfiltrating data and finally deploying their ransomware.”

A web of connections between Conti and Karakurt

The development comes as financial and tactical overlaps have been uncovered between Conti and the Karakurt data extortion group based on information published during the ContiLeaks saga, weeks after TrickBot’s operators had been subsumed into the ransomware cartel.

CyberSecurity

An analysis of blockchain transactions associated with cryptocurrency addresses belonging to Karakurt has shown “Karakurt wallets sending substantial sums of cryptocurrency to Conti wallets,” according to a joint investigation by researchers from Arctic Wolf and Chainalysis.

The shared wallet hosting is also said to involve the now-defunct TrickBot gang’s Diavol ransomware, with a “Diavol extortion address hosted by a wallet containing addresses used in Conti ransomware attacks,” indicating that Diavol is being deployed by the same set of actors behind Conti and Karakurt.

Further forensic examination of an unnamed client that was hit with a subsequent wave of extortion attacks following a Conti ransomware infection has revealed that the second group used the same Cobalt Strike backdoor left behind by Conti, implying a strong association between seemingly disparate cybercrime actors.

“Whether Karakurt is an elaborate side hustle by Conti and Diavol operatives or whether this is an enterprise sanctioned by the overall organization remains to be seen,” Arctic Wolf said.

“This connection perhaps explains why Karakurt is surviving and thriving despite some of its exfiltration-only competitors dying out,” the researchers said, adding, “Or, alternatively, perhaps this was the trial run of a strategic diversification authorized by the main group.”





Source link

Tags: computer securitycyber attackscyber newscyber security newscyber security news todaycyber security updatescyber updatesdata breachhacker newshacking newshow to hackinformation securitynetwork securityransomware malwaresoftware vulnerabilitythe hacker news
Previous Post

Firms Push for CVE-Like Cloud Bug System

Next Post

Accelerating digital transformation for the UK’s armed forces

Related Posts

Information Security

Conti Ransomware Operation Shut Down After Splitting into Smaller Groups

by admin
May 25, 2022
Information Security

Fronton IOT Botnet Packs Disinformation Punch

by admin
May 24, 2022
Information Security

Spring 2022 SOC 2 Type I Privacy report now available

by admin
May 24, 2022
Information Security

Tips to defeat social engineering attacks

by admin
May 24, 2022
Information Security

Yes, Containers Are Terrific, But Watch the Security Risks

by admin
May 24, 2022
Next Post

Accelerating digital transformation for the UK’s armed forces

Leave Comment

Recommended

KAC: Creating smarter airports that safeguard passenger journeys

May 25, 2022

Intro to ITOM & How it Impacts Cost Optimization

May 25, 2022

The Best of SWL 2022 (SupportWorld Live)

May 25, 2022

Conti Ransomware Operation Shut Down After Splitting into Smaller Groups

May 25, 2022

Fronton IOT Botnet Packs Disinformation Punch

May 24, 2022

Spring 2022 SOC 2 Type I Privacy report now available

May 24, 2022

© 2022 CIO News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy.

Navigate Site

  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

Newsletter Sign Up

No Result
View All Result
  • Home
  • News
  • Operations CIO
  • Visionary CIO
  • IT Management
  • Information Security
  • Contact

© 2022 JNews - Premium WordPress news & magazine theme by Jegtheme.