$6.8M in Bitcoin held by DarkSide ransomware group on the move

$6.8M in Bitcoin held by DarkSide ransomware group on the move
фото показано с : invezz.com

2021-10-24 15:58

Bitcoin (BTC/USD) worth $6.8 million held by the DarkSide ransomware group, which was involved in the Colonial Pipeline attack in May, is on the move, analytics company Elliptic reported, cited by CoinDesk. The analyst associates the activity with another ransomware group – REvil, which is closely connected to DarkSide.

Ransom was dormant until yesterday

After the attack on Colonial, which put the petroleum supplies of five US states at risk, DarkSide got about $5 million in ransom. Its share didn’t shift until October 21, Elliptic said Friday in a blog. At first, the victim refused to pay, but eventually did so. According to insiders, their biggest wish was to restore functionality to the biggest pipeline in the US.

Elliptic identified DarkSide wallet, ransom payments keep coming

DarkSide, who describes itself as developer of “ransomware as a service,” kept a wallet for its share of the ransom. Elliptic identified it through blockchain transaction analysis and its intelligence collection. This wallet received the ransom on May 8 after the cyberattack, which caused fuel shortages nationwide.

This wallet has been active for more than six months now. In that time, it has received 57 payments from 21 different wallets. These include ransoms known to have been paid by the group’s other victims. DarkSide has received Bitcoin transactions worth $17.5 million in total since opening the wallet, Elliptic said.

DarkSide wallet presumably claimed by REvil

DarkSide informed an unknown third party had claimed its wallet. This party sent 107.8 BTC ($6.8 million) to a new address. This sum was sent over a period of few hours through a series of new wallets, with small sums being transferred at each step, making the funds harder to trace.

US government forces REvil offline

Elliptic associates this activity with ransomware group REvil, which was hacked and forced offline in a US government-led operation this week. According to VMWare head of cybersecurity strategy Tom Kellermann, intelligence staff and law enforcement prevented the group from inflicting further damage:

The FBI, in conjunction with Cyber Command, the Secret Service and like-minded countries, have truly engaged in significant disruptive actions against these groups. REvil was top of the list.

The post $6.8M in Bitcoin held by DarkSide ransomware group on the move appeared first on Invezz.

Similar to Notcoin - TapSwap on Solana Airdrops In 2024

origin »

Trident Group (TRDT) на Currencies.ru

$ 0.0132492 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 42.85 %
Cегодня L: $0.0132492 - H: $0.0132492
Капитализация $16.072k Rank 99999
Доступно / Всего 1.213m TRDT

move ransomware group held bitcoin darkside analytics

move ransomware → Результатов: 4


Cryptojacking Outpaces RansomWare As The Biggest International Cyber Security Threat Per Kaspersky Lab

Move Over RansomWare – The Biggest International Cyber Threat Is Rapidly Becoming Illegal Cryptocurrency Mining Is Fast Taking Over The Number One Spot With the increasing growth of literacy in using computers, this means that over a billion people every year are learning to get online. But with that comes an increasing number of people […]

2018-12-15 22:56


BTC/USD Price Analysis: Price Stall at $4,300 as The US OFAC “sanction” Bitcoin Addresses

Latest Bitcoin News In a laughable move, the United States Treasury Department Office of Foreign Assets Control has issued “sanctions” against two Bitcoin addresses–149w62rY42aZBox8fGcmqNsXUzSStKeq8C and 1AjZPMsnmpdK2Rv9KQNfMurTXinscVro9V—belong to two Iranians–Ali Khorashadizadeh and Mohammad Ghorbaniyan, accused on assisting hackers launder their Bitcoin proceeds.

2018-11-30 10:15