Skip to main content

International Operation Disrupts Ransomware Group Netwalker by Tracing Cryptos With the Help of Blockchain Analysis

International Operation Disrupts Ransomware Group Netwalker by Tracing Cryptos With the Help of Blockchain Analysis

In collaboration with Bulgarian authorities, the U.S. Department of Justice (DOJ) disrupted a well-known ransomware gang’s infrastructure. Law enforcement seized their servers and traced the illicit funds with the help of blockchain forensic analytics via Chainalysis.

US Authorities Seized Over $454,000 Worth of Cryptocurrencies

Per the U.S. Department of Justice’s announcement, the coordinated action took down Netwalker, a highly active ransomware group over the last year, specifically targeting the health care sector.

The U.S. authorities also indicted a Canadian national, Sebastien Vachon-Desjardins, who allegedly obtained $27.6 million as a “Netwalker affiliate.”

The authorities seized a server that hosted their site on the dark web, where the gang redirected their victims to arrange the ransom negotiations. Moreover, the U.S. DOJ said that $454,530.19 in cryptocurrency from ransom payments were seized.

With the support of blockchain analysis, law enforcement took advantage of investigative tools of Chainalysis to trace Netwalker transactions. In fact, the blockchain firm had traced more than $46 million worth of funds in Netwalker ransoms since it first came on the scene in August 2019.

The U.S. authorities believe the ransomware gang targeted 205 victims from 27 different countries during its lifetime, including 203 in the U.S.

Speaking with news.Bitcoin.com, Brett Callow, threat analyst at malware lab Emsisoft, commented on the authorities’ action against Netwalker:

Ransomware groups have operated with almost complete impunity for a very long time, which means there’s very little deterrent. The rewards are enormous, while the risks are small. The action against Netwalker changes that. In addition to disrupting the group’s revenue stream, it also sends a clear message that cybercriminals are not beyond the reach of the law. Will that create a deterrent? No, but it’s certainly a step in the right direction.

Netwalker ransomware works with an affiliate scheme, where external people could deploy the ransomware and share revenues with the gang. Chainalysis elaborates on what the blockchain analysis unveiled about the infrastructure:

Typically, there are four roles that receive proceeds from Netwalker attacks: the likely administrator or developer (8-10%), the affiliate (76-80%), and two commissioned roles (2.5%-5% each). An affiliate, like Vachon-Desjardins, is usually responsible for obtaining access to the victim network and deploying the malware. There are also cases when one wallet gets 100% of the payment, which we believe belongs to the Netwalker administrator and indicates that he or she may also be directly involved in some of the attacks.

The analytical firm says that there were fewer than 20 unique affiliates. Some of them rarely deployed the ransomware, while others moved on to other similar ransomware strains. That’s why a tool used by the authorities named Chainalysis Reactor traced payments received by the affiliates from other variants.

To confirm the fact that some affiliates moved to other strains, Chainalysis found out that Netwalker administrator published an advertisement on darknet forums. The admin was seeking new affiliates, as vacancies “had freed up.”

Tracing Suspected Netwalker Affiliate

On how the authorities traced Vachon-Desjardins’ activities, Chainalysis explained:

Blockchain analysis revealed at least 345 addresses associated with Vachon-Desjardins going back to February 2018 with transactions continuing to the date of this writing (January 27, 2021). He allegedly received more than $14 million worth of bitcoin at the time of receipt of the funds, ultimately possessing at least $27.6 million given its rising value.

Citing government partners, Chainalysis claims Vachon-Desjardins was involved in at least 91 attacks using Netwalker ransomware since April 2020, deploying the malware as an affiliate and receiving 80% of the ransom. The analytical firm also suspects the alleged Netwalker affiliate was involved in the deployment of other ransomware strains.

What do you think about this massive operation against the Netwalker ransomware gang? Let us know in the comments section below.



from Bitcoin News https://ift.tt/3ai7VTq

Comments

Popular posts from this blog

Mt Gox Creditors Updated, Trustee Says Rehabilitation Custodian Is ‘Currently Preparing to Make Repayments’

On August 31, 2022, the Mt Gox trustee Nobuaki Kobayashi explained in a recent letter that the rehabilitation custodian is “currently preparing to make repayments” to Mt Gox creditors. Trustee Updates Mt Gox Creditors — Repayment Date and Exchange Still Unknown Last week speculation and rumors concerning the release of 140K bitcoin ( BTC ) from Mt Gox littered social media platforms and headlines. Bitcoin.com News covered the situation six days ago as a number of people and Mt Gox creditors called the rumors “ fake news .” During that same period of time, a bitcoin whale transferred 10,000 BTC to unknown wallets, and a 2018 annotation , heuristics, and clustering methods show the funds likely originated from the June 2011 Mt Gox hacks. Following the mysterious whale transfer, last Wednesday, Mt Gox published an official update from the court trustee Nobuaki Kobayashi that explains the court is “currently preparing to make repayments” to creditors. Mt Gox creditors have been wait...

Fidelity Discusses Bitcoin as Portfolio Insurance — Could Soon Stand in ‘Stark Contrast’ to Path Fiat Currencies Take

Fidelity Digital Assets, a subsidiary of Fidelity Investments, says that bitcoin could be considered portfolio insurance. The firm notes that the cryptocurrency “may soon stand in stark contrast to the path that the rest of the world and fiat currencies may take — namely the path of increased supply, additional currency creation, and central bank balance sheet expansion.” Fidelity Says Bitcoin Could Be Portfolio Insurance Fidelity Digital Assets, a subsidiary of Fidelity Investments, recently published a research study titled “The Rising Dollar and Bitcoin.” The research outlines “how bitcoin could be considered portfolio insurance” as the rising dollar impacts global currency markets. “The strengthening U.S. dollar is wreaking havoc among other countries and may put pressure on the Federal Reserve to soon reverse its tightening monetary actions, something that has precedent based on 1985’s Plaza Accord,” Fidelity explained. In addition, “more monetary debasement may be needed to ...

Economists Discuss Russia, China Potentially Developing Gold-Backed Currency That Could Undermine US Dollar

Economists have weighed in on reports that China and Russia may be developing a new gold-backed currency that could undermine the U.S. dollar’s status as the world’s primary reserve currency. Russia and China May Be Developing Gold-Backed Currency Several experts have shared their views on Russia and China potentially creating a new gold-baked currency, Fox Business reported Saturday, emphasizing that China has been buying up huge quantities of gold while Russia was forced off the U.S. dollar due to sanctions imposed on the country following its invasion of Ukraine. The news outlet noted that some experts have cautioned that these moves, along with the closer relationship that has developed between Moscow and Beijing, point to the likelihood of China attempting to launch a gold-backed currency. However, neither Russia nor China has officially confirmed plans for such a currency. Craig Singleton, senior fellow at the Foundation for Defense of Democracies and a former U.S. diplomat,...