Back to photostream

DarkSide ransomware servers reportedly seized, operation shuts down

The DarkSide ransomware servers operation has allegedly shut down after the threat actors lost access to servers and their cryptocurrency was transferred to an unknown wallet.

 

This news was shared by a threat actor known as 'UNKN', the public-facing representative of the rival REvil ransomware gang, in a forum post first discovered by Recorded Future researcher Dmitry Smilyanets on the Exploit hacking forum.

 

DarkSide ransomware servers reportedly seized, operation shuts down.

 

Forum post by UKNK about DarkSide seizure | Source: Dmitry Smilyanet

 

In the post, 'Unkn' shared a message allegedly from DarkSide explaining how the threat actors lost access to their public data leak site, payment servers, and CDN servers due to law enforcement action.

 

"Since the first version, we have promised to speak honestly and openly about problems. A few hours ago, we lost access to the public part of our infrastructure, namely : Blog, Payment server, DOS servers," reads the forum post from UNKN.

 

"Now these servers are unavailable via SSH, the hosting panels are blocked. Hosting support, apart from information "at the request of law enfocement agencies", does not provide any other information."

 

This news comes a day after President Biden said in a White House press conference that countries harboring ransomware networks must take action to shut them down.

 

"We do not believe — I emphasize, we do not believe the Russian government was involved in this attack.

 

technogeek.online/darkside-ransomware-servers-reportedly-...

225 views
0 faves
0 comments
Uploaded on May 17, 2021