Renamed Russian ransomware projects to avoid western sanctions: report

Renamed Russian ransomware projects to avoid western sanctions: report

The blockchain secret service company TRM Labs announced that some large ransomware syndicates associated with Russia renamed their activities in 2022 to avoid sanctions of western countries.

according to A New report The recently published rebranding and other significant activities showed remarkable changes in the field of cybercrime and the Darknet markets (DNMS) after Russia marched into Ukraine.

Ransomware operator renamed to avoid sanctions

After the Russian invasion in Ukraine, several western law enforcement authorities imposed stricter sanctions against Russian ransomware platforms.

similar, sanctions The ransomware projects imposed by the US Office of Foreign Assets Control (OFAC) of the popular Darknet platform Hydra demanded their toll when they get offset Law enforcement authorities.

In order to strengthen their anonymity through changes in on-chain behavior, two large Ransomware syndicates, attracting bit and conti have structured their activities.

Through the on-chain analysis of TRM, open source reports and proprietary information, the intelligence company discovered that Conti stopped its original company and restructured itself in three smaller groups called Black Basta, Blackbyte and Karakut. Before the diversification, Karakut was a side project by the Conti operator.

Lockbit, on the other hand, renamed his activities since Ukraine's invasion last February. Four months later, the Syndika Lockbit 3.0 started, which forecast it as apolitical and focused on monetary profits.

"The claim of Lockbit that it was not intended to intentionally attack Western countries could have been motivated by the possibility of Western sanctions against Russian companies. In addition, attracting bit said that it had banned attacks on companies in connection with critical infrastructure, probably to minimize the risk of the attention of the law enforcement authorities and possible sanctions," said TRM.

Western sanctions had little influence on DNMS

In addition, the analysis of TRM also showed Significant growth when using Russian-speaking Darknet markets. Due to sanctions against DNMS, criminals fled on platforms with a Russian reference to escape western law enforcement.

Overall, the Russian-speaking Darknet markets recorded several phases of growth between April-Juli and October-December 2022. They had achieved sales of over $ 130 million by the end of the year.

.

Kommentare (0)