The Infrastructure Boss
What does a former Boris Yeltsin era Defense Minister for the Russian Federation have to do with cybercrime and ransomware today?
| Typosquatting Mikhail. |
| Typosquatting Mikhail. |
By Dominic Alvieri
January 30th, 2023
In the early morning hours of Thursday, January 26th a multi-governmental offensive seized the Hive Ransomware leak site. No arrests have been made in the never ending ransomware whack-a-mole game. LockBit is now the undisputed leading ransomware operation.
That evening LockBit was ready with a new game, comments and plenty of leaks ready to go. The Hive Ransomware leak site was seized early Thursday morning and the first comment or post from LockBit was a freaking game below.
The post above was removed by LockBit. Researchers at VX Underground were able to get a comment from Mr. LockBit about the post and the news that followed. LockBit is one group I do not have communications with and do not care to.
By Sunday evening it was business as usual as LockBit posted affiliate offerings of 14 new victims not willing to pay them from around the world.
Spain
France
Mexico
Austria
Albania
Portugal
Australia
United States
United Kingdom
Low lights from the new posts include PBS member television station KVIE in Sacramento, California, Air Albania, CPL Industries...
LockBit is clearly the top operation remaining and is arrogantly making it known. Alphv Black Cat Ransomware is behind LockBit and there is a clear distinction from the remaining groups including new up and coming Play Ransomware, Black Basta, Vice Society...
Several other groups and former members are not included in this article including Black Matter, DarkSide and the other variations, spinoffs and new groups pending like Endurance Ransomware.
No Hive arrests to date.
Affiliates have to go somewhere...
The never ending ransomware whack-a-mole game continues in 2023.
The Cyber Show
By Dominic Alvieri
October 12th, 2022
A new Chinese misinformation campaign has been spreading this past week attempting to attribute the Chinese APT 41 to the National Security Agency. Many are using the Intrusion Truth name.
Global Times Chinese domain article tweet.
Several new accounts tweeted in Chinese Mandarin for the local media in Asia while others have been created in English for a wider audience. All accounts use the APT 41 hashtag.
The above tweet translates to FireEye attributing Chinese APT 41 to the NSA.
The tweet above has been removed but the account remains.
The FBI reports concludes what we all know while some are trying to create confusion in typical APT 41 style.
This is a new and current campaign with all accounts still currently open. No new activity has been spotted since the initial report this week with fake attribution tweets.
Blog will be updated as needed. Stay safe.
By Dominic Alvieri
3-9-2022
More and more services and communications that were once reserved for the deepest depths of the DarkWeb are crawling up the stack, if you will to social media platforms. Ransomware group posts are now mainstream on Telegram and Twitter with calls for action, mis or disinformation and fake data leaks.
Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...