DOJ says it disrupted a major global ransomware group

The US Department of Justice has spent months infiltrating and disrupting the Hive ransomware group, the agency announced on Thursday. The DOJ says Hive has targeted over 1,500 victims in more than 80 countries, extorting hundreds of millions of dollars in ransom payments.

Working with German and Netherlands law enforcement, the FBI seized Hive’s servers and websites, allegedly slowing the group’s ability to attack and extort new victims. It first infiltrated Hive’s network in July 2022, providing over 300 decryption keys to Hive’s current victims and more than 1,000 keys to previous victims — preventing over $130 million in ransom payments. The agency hasn’t announced any arrests. However, it’s still investigating the group, according toNBC News.

Hive used a ransomware-as-a-service (RaaS) model, where administrators (essentially the ringleaders) create ransomware strains with easy-to-use interfaces. The administrators then recruit affiliates who use the ransomware software to carry out the theft — and likely much of the risk.

For example, Hive would steal a victim’s data and encrypt their system. The affiliate would then demand a ransom in exchange for the decryption key and a promise not to publish the data. (Of course, it would frequently target the most sensitive data to apply maximum pressure.) If the victims pay, affiliates and administrators would split the ransom 80 / 20. Those unwilling to pay would find their data leaked on the web.

US Attorney General Merrick Garland speaks during a press conference to announce an international ransomware enforcement action, at the Justice Department in Washington, DC, on January 26, 2023. - The US Justice Department announced Thursday it had shut down the Hive ransomware operation, which had extorted more than $100 million from more than 1,500 victims worldwide. (Photo by Mandel NGAN / AFP) (Photo by MANDEL NGAN/AFP via Getty Images)
MANDEL NGAN via Getty Images

The US Cybersecurity and Infrastructure Security Agency (CISA) says Hive gained access through single-factor logins via Remote Desktop, VPNs, exploiting FortiToken (software-based access key) vulnerabilities and phishing emails with malicious attachments.

“Last night, the Justice Department dismantled an international ransomware network responsible for extorting and attempting to extort hundreds of millions of dollars from victims in the United States and around the world,” said US Attorney General Merrick Garland today. “We will continue to work both to prevent these attacks and to provide support to victims who have been targeted. And together with our international partners, we will continue to disrupt the criminal networks that deploy these attacks.” The FBI recommends victims contact their local FBI field office.

Five Memphis Cops Charged In Tyre Nichols Death

How To Turn Your Wi-Fi Password Into A QR Code

If you find yourself having to give out your Wi-Fi password a lot, a nice hack is to turn it into a QR code and post it somewhere where visitors can scan it.

These Mercedes Cars Are One Big Step Closer To Self-Driving: Here's What They Can (And Can't) Do

Mercedes-Benz’s Drive Pilot autonomous driving system is set to arrive in the United States – here are the cars that will get it first.

The Audi Activesphere Concept Is An Electric Crossover With A Pickup Tailgate And A Secret Mission

The Audi Activesphere is an enigma: It rolls with key features of several conflicting sorts of vehicles, yet seems to meld the bunch into one attractive ride.

Amazon Warns Employees to Beware of ChatGPT

ChatGPT has been making the tech industry sweat since its rise in popularity last year, and now Amazon is feeling the heat too. According to internal communications from the company as viewed by Insider, an Amazon lawyer has urged employees not to share code with the AI chatbot.

Read more…

National Threat Assessment Center Releases First of Its Kind Report on Mass Attacks

A white supremacist killed 10 people and injured three others in a Buffalo, New York supermarket in May 2022. While the gunman was carrying out his heinous act of violence, he was also livestreaming the shooting on Twitch. For months leading up to the attack, the shooter posted about his plans on Discord. The 19-year…

Read more…

What You Need to Know About Critical Role's Mighty Nein

The Legend of Vox Machina has been so successful that it was no surprise when Prime Video announced a third season of Critical Role’s animated fantasy was in development—or when the streamer confirmed that the beloved TTRPG’s second campaign, The Mighty Nein, is now getting an adaptation of its own.

Read more…

Size Does Matter: PlayStation Edge Controller’s Shrunken Battery Explains Its Shorter Operating Life

The $200 PlayStation 5 Dualsense Edge controller Sony announced last year is meant to provide ultimate try-hard gamers with new options to stomp their opponents. However paying the extra $130 over than the original DualSense’s $70 to access those extra bells and whistles also means cutting a marathon gaming session…

Read more…

Uber Eats now shows users which of their personal details couriers can see

The next time you order something from Uber Eats, you’ll be able to find out what personal information of yours a courier can see at each stage of the delivery process. The View as Delivery Person feature follows a View as Driver function Uber added in 2020. Starting today, Uber Eats users in the US and Canada can access the information from the recent order page and in the app’s privacy center (under the privacy menu on the account tab).

The delivery person will only know an approximate delivery location until they collect the order. Then they’ll typically have access to your first name, initial of your last name and exact delivery location. Uber will provide them with your delivery instructions and notes too. After the order is completed, the courier will once again only see a general delivery location in their app.

Moreover, the feature will tell you what kinds of details couriers can’t see, such as your phone number, payment details or driver rating. If you order products like alcohol or weed through Uber Eats, you need to prove you’re of legal age by sharing a picture of your ID. Couriers can’t see your ID details after they make the delivery, Uber says.

The idea is to provide users with more peace of mind and transparency, as Zach Singleton, Uber’s head of privacy and equity product, told The Verge. View as Driver was a popular privacy feature among users, according to Singleton, who noted that Uber receives thousands of support tickets from users who are concerned about how much personal information their driver or courier gets, as well as those eager to know more.

Safety is a critical concern for many Uber and Uber Eats users. Singleton added that women are “53 percent more likely to have a concern about the information that delivery people had when something uncomfortable has occurred.”