{"id":2234,"date":"2023-12-20T20:33:00","date_gmt":"2023-12-20T20:33:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cybersecurity-operations\/blackcat-unseizes-sites-fbi-revenge-attacks"},"modified":"2023-12-20T20:33:00","modified_gmt":"2023-12-20T20:33:00","slug":"defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/20\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks\/","title":{"rendered":"Defiant BlackCat Gang Stands Up New Site, Calls for Revenge Attacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt84fc46f9278e9b25\/6583411cc37f3d0407fe4f59\/black_cat_Saro_o_Neal_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">BlackCat\/ALPHV ransomware leaders claim they have restarted operations on the group&#8217;s primary blog, despite the Department of Justice claim that it gained control of the site. Further, in retaliation for the law enforcement actions against the gang, they announced they have dropped a previous ban on cyberattacks against critical infrastructure.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/everything-you-need-to-know-about-blackcat-alphav-\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">BlackCat<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> also claimed that, beyond &#8220;unseizing&#8221; the sites, the decryption key being offered by the FBI is outdated and from an older blog, according to a reading of the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/flashpoint.io\/blog\/alphvs-downfall-crackdown-blackcat-ransomware\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">group&#8217;s message<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> from Dec. 19 by Flashpoint researchers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It&#8217;s a bold claim, but experts have their doubts about BlackCat&#8217;s ability to mount such a quick comeback.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">BlackCat Didn&#8217;t &#8216;Unseize&#8217; Its Blog<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">First, the data and server have indeed been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/feds-snarl-alphv-blackcat-ransomware-operation\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">seized by the FBI<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and there are no takebacks, Steve Stone from Rubrik Zero Labs explains. Stone tells Dark Reading the idea of &#8220;seizing&#8221; and &#8220;unseizing&#8221; the site is being widely misunderstood in the public discourse.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Put simply, the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/alphv-blackcat-takedown-appears-to-be-law-enforcement-related\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">FBI and other law enforcement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> organizations have successfully seized control of a data repository and also took control of\/took down the ALPHV site they used to run their ransomware-as-a-service (RaaS) operations,&#8221; Stone says. &#8220;ALPHV has responded by spinning up a new server and applying their security key, which makes this the new site.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Next, the FBI will revert the new site to the old one already in their control, and the cycle continues, he predicts.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The FBI then works to revert it to the original\/seized one,&#8221; Stone says. &#8220;Then ALPHV does it again, as we saw yesterday.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Heightened Critical Infrastructure Ransomware Threat<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, the threat of fresh <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/ransomware-data-breaches-inundate-ot-industrial-sector\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">cyberattacks on critical infrastructure<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as a result of BlackCat&#8217;s lifting of restrictions for its affiliates is very real, cybersecurity insiders warn.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Given ALPHV&#8217;s new stance, there is a real possibility of an increase in cyberattacks on critical infrastructure,&#8221; says Chris Grove, director of cybersecurity strategy for Nozomi Networks. &#8220;Organizations operating critical infrastructure should be on heightened alert, as these developments could re-awaken a dormant phase in cybercriminal tactics where CI is fair play.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ransomware is a lucrative business and BlackCat isn&#8217;t likely to give it up without a fight, Grove adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Although this group&#8217;s operations are degraded, they might act out of desperation to maintain their image as a safe system for hackers to leverage for their criminal activities,&#8221; Grove says. &#8220;In a short period of time they&#8217;ve been able to pull in $300 million to fund these types of operations, something they will fight for at the expense of our society&#8217;s safety and peace.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/blackcat-unseizes-sites-fbi-revenge-attacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BlackCat\/ALPHV ransomware leaders claim they have restarted operations on the<\/p>\n","protected":false},"author":12,"featured_media":2235,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2234","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=2560%2C1552&ssl=1",2560,1552,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=300%2C182&ssl=1",300,182,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=640%2C388&ssl=1",640,388,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=640%2C388&ssl=1",640,388,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=1536%2C931&ssl=1",1536,931,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=2048%2C1242&ssl=1",2048,1242,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=1024%2C621&ssl=1",1024,621,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/defiant-blackcat-gang-stands-up-new-site-calls-for-revenge-attacks-scaled.jpg?fit=2560%2C1552&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2234","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2234"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2234\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2235"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2234"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2234"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2234"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}