Fun

International Operation Disrupts Ransomware Group Netwalker by Tracing Cryptos With the Help of Blockchain Analysis

News Feed - 2021-01-29 05:01:44

International Operation Disrupts Ransomware Group Netwalker by Tracing Cryptos With the Help of Blockchain Analysis


In collaboration with Bulgarian authorities, the U.S. Department of Justice (DOJ) disrupted a well-known ransomware gang’s infrastructure. Law enforcement seized their servers and traced the illicit funds with the help of blockchain forensic analytics via Chainalysis. US Authorities Seized Over $454,000 Worth of Cryptocurrencies


Per the U.S. Department of Justice’s announcement, the coordinated action took down Netwalker, a highly active ransomware group over the last year, specifically targeting the health care sector.


The U.S. authorities also indicted a Canadian national, Sebastien Vachon-Desjardins, who allegedly obtained $27.6 million as a “Netwalker affiliate.”


The authorities seized a server that hosted their site on the dark web, where the gang redirected their victims to arrange the ransom negotiations. Moreover, the U.S. DOJ said that $454,530.19 in cryptocurrency from ransom payments were seized.


With the support of blockchain analysis, law enforcement took advantage of investigative tools of Chainalysis to trace Netwalker transactions. In fact, the blockchain firm had traced more than $46 million worth of funds in Netwalker ransoms since it first came on the scene in August 2019.


The U.S. authorities believe the ransomware gang targeted 205 victims from 27 different countries during its lifetime, including 203 in the U.S.


Speaking with news.Bitcoin.com, Brett Callow, threat analyst at malware lab Emsisoft, commented on the authorities’ action against Netwalker: Ransomware groups have operated with almost complete impunity for a very long time, which means there’s very little deterrent. The rewards are enormous, while the risks are small. The action against Netwalker changes that. In addition to disrupting the group’s revenue stream, it also sends a clear message that cybercriminals are not beyond the reach of the law. Will that create a deterrent? No, but it’s certainly a step in the right direction.


Netwalker ransomware works with an affiliate scheme, where external people could deploy the ransomware and share revenues with the gang. Chainalysis elaborates on what the blockchain analysis unveiled about the infrastructure: Typically, there are four roles that receive proceeds from Netwalker attacks: the likely administrator or developer (8-10%), the affiliate (76-80%), and two commissioned roles (2.5%-5% each). An affiliate, like Vachon-Desjardins, is usually responsible for obtaining access to the victim network and deploying the malware. There are also cases when one wallet gets 100% of the payment, which we believe belongs to the Netwalker administrator and indicates that he or she may also be directly involved in some of the attacks.


The analytical firm says that there were fewer than 20 unique affiliates. Some of them rarely deployed the ransomware, while others moved on to other similar ransomware strains. That’s why a tool used by the authorities named Chainalysis Reactor traced payments received by the affiliates from other variants.


To confirm the fact that some affiliates moved to other strains, Chainalysis found out that Netwalker administrator published an advertisement on darknet forums. The admin was seeking new affiliates, as vacancies “had freed up.”


Tracing Suspected Netwalker Affiliate


On how the authorities traced Vachon-Desjardins’ activities, Chainalysis explained: Blockchain analysis revealed at least 345 addresses associated with Vachon-Desjardins going back to February 2018 with transactions continuing to the date of this writing (January 27, 2021). He allegedly received more than $14 million worth of bitcoin at the time of receipt of the funds, ultimately possessing at least $27.6 million given its rising value.


Citing government partners, Chainalysis claims Vachon-Desjardins was involved in at least 91 attacks using Netwalker ransomware since April 2020, deploying the malware as an affiliate and receiving 80% of the ransom. The analytical firm also suspects the alleged Netwalker affiliate was involved in the deployment of other ransomware strains.


What do you think about this massive operation against the Netwalker ransomware gang? Let us know in the comments section below. Study: 60% of Digital Asset Holders Store Funds on Exchanges While Half Derive an Income From Crypto SECURITY | 5 hours ago Network-Attached Storage (NAS) Devices Infected by Bitcoin-Mining Malware SECURITY | 21 hours ago Tags in this story Chainalysis, cybersecurity, doj seizes bitcoin, Netwalker, ransomware, ransomware research, seized, U.S Department of Justice (DoJ)


Image Credits: Shutterstock, Pixabay, Wiki Commons Use Bitcoin and Bitcoin Cash to play online casino games here. Show comments

News Feed

Quppy Users Are Offered a Referral Program
Quppy Users Are Offered a Referral Program PRESS RELEASE. Quppy services can now be referred for an attractive direct cashback.
Tom Blackstone9 hours agoFarmville co-creator-led company raises $33M to create Web3 gamesProof of Play raised $33 million to create fully on-chain games that “quickly immerse players in fun gameplay.“1504 Total view
Analyst Backs Spot Bitcoin ETFs To Surpass Gold ETFs In Cumulative Net Inflows
Este artículo también está disponible en español. Market analyst and President of the ETF Store Nate Geraci has backed the US-based spot Bitcoin ETFs to overtake the Gold
All Tifon Gas Stations in Croatia Now Accept Cryptocurrencies
All Tifon Gas Stations in Croatia Now Accept Cryptocurrencies Forty-six Tifon gas stations across Croatia have reportedly started accepting cryptocurrency paymen
Bitcoin, Ethereum Technical Analysis: BTC Hits 1-Week Low, Bullish Sentiment Fades on Monday
Bitcoin, Ethereum Technical Analysis: BTC Hits 1-Week Low, Bullish Sentiment Fades on Monday Bitcoin fell to a seven-day low to start the week, as recent bullish momentum began to
ZachXBT won’t assist after memecoin devs throw tokenholders under the bus
Zhiyuan Sun4 hours agoZachXBT won’t assist after memecoin devs throw tokenholders under the bus“Together, let’s stand against harassment and prioritize mental health in all aspects of our lives,” wrote Complex’
Sam Bankman-Fried sentenced to 25 years in prison
Turner Wright8 hours agoSam Bankman-Fried sentenced to 25 years in prisonJudge Lewis Kaplan found that the former FTX CEO also committed witness tampering and perjury based on his testimony at trial over user funds.11300
Solana Sees Renewed Demand As Capital Flows Turn Positive – Details
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu
Cointelegraph11 hours agoZK community aligned with the core Web3 mission: ZkDay Istanbul roundupThe ZkDay Istanbul event offered exposure and networking opportunities to new and upcoming ZK-based projects and entrepreneu
Nasdaq-Listed Microstrategy Obtains $205 Million Bitcoin-Backed Loan to Buy More BTC
Nasdaq-Listed Microstrategy Obtains $205 Million Bitcoin-Backed Loan to Buy More BTC Nasdaq-listed Microstrategy has obtained a $205 million bitcoin-collateralized loan from Silver
UK authorities will soon have less restrictions when seizing crypto
Ciaran Lyons6 hours agoUK authorities will soon have less restrictions when seizing cryptoFrom April 26, the UK economic crime legislation will include civil recovery orders for confiscating crypto assets.3263 Total view
NFT Market Sales Climb 16% Higher; 43.48% Increase in Buyers in Third Week of 2023
NFT Market Sales Climb 16% Higher; 43.48% Increase in Buyers in Third Week of 2023 Closing out the third week of January 2023, non-fungible token (NFT) assets saw a 16.39% increase