International Operation Disrupts Ransomware Group Netwalker by Tracing Cryptos With the Help of Blockchain Analysis

International Operation Disrupts Ransomware Group Netwalker by Tracing Cryptos With the Help of Blockchain Analysis
фото показано с : news.bitcoin.com

2021-1-29 11:30

In collaboration with Bulgarian authorities, the U.S. Department of Justice (DOJ) disrupted a well-known ransomware gang’s infrastructure. Law enforcement seized their servers and traced the illicit funds with the help of blockchain forensic analytics via Chainalysis.

US Authorities Seized Over $454,000 Worth of Cryptocurrencies

Per the U.S. Department of Justice’s announcement, the coordinated action took down Netwalker, a highly active ransomware group over the last year, specifically targeting the health care sector.

The U.S. authorities also indicted a Canadian national, Sebastien Vachon-Desjardins, who allegedly obtained $27.6 million as a “Netwalker affiliate.”

The authorities seized a server that hosted their site on the dark web, where the gang redirected their victims to arrange the ransom negotiations. Moreover, the U.S. DOJ said that $454,530.19 in cryptocurrency from ransom payments were seized.

With the support of blockchain analysis, law enforcement took advantage of investigative tools of Chainalysis to trace Netwalker transactions. In fact, the blockchain firm had traced more than $46 million worth of funds in Netwalker ransoms since it first came on the scene in August 2019.

The U.S. authorities believe the ransomware gang targeted 205 victims from 27 different countries during its lifetime, including 203 in the U.S.

Speaking with news.Bitcoin.com, Brett Callow, threat analyst at malware lab Emsisoft, commented on the authorities’ action against Netwalker:

Ransomware groups have operated with almost complete impunity for a very long time, which means there’s very little deterrent. The rewards are enormous, while the risks are small. The action against Netwalker changes that. In addition to disrupting the group’s revenue stream, it also sends a clear message that cybercriminals are not beyond the reach of the law. Will that create a deterrent? No, but it’s certainly a step in the right direction.

Netwalker ransomware works with an affiliate scheme, where external people could deploy the ransomware and share revenues with the gang. Chainalysis elaborates on what the blockchain analysis unveiled about the infrastructure:

Typically, there are four roles that receive proceeds from Netwalker attacks: the likely administrator or developer (8-10%), the affiliate (76-80%), and two commissioned roles (2.5%-5% each). An affiliate, like Vachon-Desjardins, is usually responsible for obtaining access to the victim network and deploying the malware. There are also cases when one wallet gets 100% of the payment, which we believe belongs to the Netwalker administrator and indicates that he or she may also be directly involved in some of the attacks.

The analytical firm says that there were fewer than 20 unique affiliates. Some of them rarely deployed the ransomware, while others moved on to other similar ransomware strains. That’s why a tool used by the authorities named Chainalysis Reactor traced payments received by the affiliates from other variants.

To confirm the fact that some affiliates moved to other strains, Chainalysis found out that Netwalker administrator published an advertisement on darknet forums. The admin was seeking new affiliates, as vacancies “had freed up.”

if (!window.GrowJs) { (function () { var s = document.createElement('script'); s.async = true; s.type = 'text/javascript'; s.src = 'https://bitcoinads.growadvertising.com/adserve/app'; var n = document.getElementsByTagName("script")[0]; n.parentNode.insertBefore(s, n); }()); } var GrowJs = GrowJs || {}; GrowJs.ads = GrowJs.ads || []; GrowJs.ads.push({ node: document.currentScript.parentElement, handler: function (node) { var banner = GrowJs.createBanner(node, 31, [300, 250], null, []); GrowJs.showBanner(banner.index); } });

Tracing Suspected Netwalker Affiliate

On how the authorities traced Vachon-Desjardins’ activities, Chainalysis explained:

Blockchain analysis revealed at least 345 addresses associated with Vachon-Desjardins going back to February 2018 with transactions continuing to the date of this writing (January 27, 2021). He allegedly received more than $14 million worth of bitcoin at the time of receipt of the funds, ultimately possessing at least $27.6 million given its rising value.

Citing government partners, Chainalysis claims Vachon-Desjardins was involved in at least 91 attacks using Netwalker ransomware since April 2020, deploying the malware as an affiliate and receiving 80% of the ransom. The analytical firm also suspects the alleged Netwalker affiliate was involved in the deployment of other ransomware strains.

What do you think about this massive operation against the Netwalker ransomware gang? Let us know in the comments section below.

Similar to Notcoin - Blum - Airdrops In 2024

origin »

High Performance Blockchain (HPB) на Currencies.ru

$ 0 (+0.00%)
Объем 24H $0
Изменеия 24h: 0.00 %, 7d: 0.00 %
Cегодня L: $0 - H: $0.0064459
Капитализация $0 Rank 99999
Цена в час новости $ 0.0910131 (-100%)

blockchain help ransomware enforcement seized law gang

blockchain help → Результатов: 126


Italy Calls Experts To Help In The Development Of Its Official Blockchain Strategy

Italy Calls Experts To Help In The Development Of Its Official Blockchain Strategy The Italian government wants to expand the integration of the blockchain technology in the state organizations. To do it, the government has decided to call 30 high-level blockchain experts that will help to integrate the technology in the country’s institutions. According to […]

2018-12-28 20:48


Cryptocurrency Billionaire Brock Pierce Believes Blockchain Can Save Puerto Rico

According to ABC, cryptocurrency billionaire Brock Pierce believes that he can help contribute to Puerto Rico’s economic development through investments in blockchain technology. Not only can blockchain technology help with immediate disaster relief for local Puerto Ricans, it can also contribute to their struggling economy and help the country to become an international hub of […]

2018-7-27 16:25


DressCode ICO

DressCode is creating a platform the builds on the reality of a limited edition fashion frenzy on the blockchain, which with a help of the latest technology, authenticates, certifies and traces; and in so doing enables the community to buy/sell, bid/ask for the most sought after objects of desire.

2018-7-27 01:26


Cryptocurrency Billionaire Brock Pierce Believes Blockchain Can Save Puerto Rico

According to ABC, cryptocurrency billionaire Brock Pierce believes that he can help contribute to Puerto Rico’s economic development through investments in blockchain technology. Not only can blockchain technology help with immediate disaster relief for local Puerto Ricans, it can also contribute to their struggling economy and help the country to become an international hub of… The post Cryptocurrency Billionaire Brock Pierce Believes Blockchain Can Save Puerto Rico appeared first on UNHASHED.

2018-7-26 20:59


Margin ICO

Margin is a Wanchain-enabled targeted loan platform and one of the first peer-to-peer lending solutions on the blockchain. Margin's pioneering lending model enables it to offer a kind of loan that the traditional banking industry has never offered: a 0% APR loan backed by the MRG treasury to borrowers in verifiable debt-trap situations.

2018-7-24 22:18


STARKs, Part I: Proofs with Polynomials

Special thanks to Eli Ben-Sasson for ongoing help, explanations and review, coming up with some of the examples used in this post, and most crucially of all inventing a lot of this stuff; thanks to Hsiao-wei Wang for reviewing Hopefully many people by now have heard of ZK-SNARKs, the general-purpose succinct zero knowledge proof technology that can be used for all sorts of usecases ranging from verifiable computation to privacy-preserving cryptocurrency.

2018-7-21 23:03


Farmobile DataStore Unveils First Blockchain Farm Data Exchange

Farmobile LLC, an Independent Farm Data Company, has announced that the Farmobile DataStore exchange is now open for business, connecting data buyers and farmers nationwide. The release represents the Farmobile team’s commitment to help farmers derive a revenue stream from their farm data by connecting them to buyers through an accessible, interactive process. It is […]

2018-7-19 13:50