{"id":4837,"date":"2024-08-13T13:08:36","date_gmt":"2024-08-13T18:08:36","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers"},"modified":"2024-08-13T13:08:36","modified_gmt":"2024-08-13T18:08:36","slug":"fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/13\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers\/","title":{"rendered":"FBI Shuts Down Dozens of Radar\/Dispossessor Ransomware Servers"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt15805ce5396fcec7\/66bb647a1c62a61e1953f603\/Ransomware_Zoonar_GmbH_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The FBI has shut down dozens of servers associated with the Radar\/Dispossessor ransomware operations, disrupting a group that originally piggybacked on activity of an existing ransomware gang but eventually became its own cybercriminal force to be reckoned with.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The agency dismantled various pieces of the group&#8217;s global computer infrastructure, including three servers in the US; three in the UK; 18 servers in Germany; eight US-based criminal domains; and one German-based criminal domain, FBI Cleveland <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.fbi.gov\/contact-us\/field-offices\/cleveland\/news\/international-investigation-leads-to-shutdown-of-ransomware-group?7194ef805fa2d04b0f7e8c9521f97343\" rel=\"noopener\">revealed<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in a press release this week.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Radar\/Dispossessor, operated by a person with the online moniker &#8220;Brain,&#8221; first came onto the cybercriminal scene in August 2023 as an operation that published data stolen by the LockBit ransomware gang in an attempt to profit from it, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.sentinelone.com\/blog\/ransomware-evolution-how-cheated-affiliates-are-recycling-victim-data-for-profit\/\" rel=\"noopener\">according to researchers<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> at SentinelOne. However, it soon evolved into a full-fledged ransomware gang of its own.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At the time of the FBI bust, the group had developed into an international ransomware gang with a particular focus on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/ransomware-with-an-identity-crisis-targets-small-businesses-individuals\" rel=\"noopener\">small-to-mid-sized businesses<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (SMBs) and organizations from the production, development, education, healthcare, financial services, and transportation sectors, according to the law enforcement organization.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The FBI conducted its investigation and subsequent takedown of the group&#8217;s infrastructure in collaboration with the the UK&#8217;s National Crime Agency, Bamberg Public Prosecutor&#8217;s Office, Bavarian State Criminal Police Office (BLKA), and US Attorney&#8217;s Office for the Northern District of Ohio.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Relentless Double-Extortion Pressure\">Relentless Double-Extortion Pressure<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Radar\/Dispossessor originally attacked US organizations but eventually branched out globally; the FBI identified 43 victims from not only the US but also Argentina, Australia, Belgium, Brazil, Honduras, India, Canada, Croatia, Peru, Poland, the UK, the United Arab Emirates, and Germany.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;During its investigation, the FBI identified a multitude of websites associated with Brain and his team,&#8221; according to the release.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Like many other groups, Radar\/Dispossessor used <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/money-ransomware-enters-double-extortion-fray-\" rel=\"noopener\">double extortion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as its criminal model, exfiltrating organizations&#8217; critical data in attacks to hold for ransom in addition to encrypting their computer systems. Its typical attacks included finding vulnerabilities, using weak passwords, and discovering a lack of two-factor authentication (2FA) as an entry point into victim systems. Once initial access was gained, the group escalated privileges to admin status to gain access to files and then deployed ransomware-based encryption from there.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The group was known for being relentless in its pursuit of a ransom payment, according to the FBI. Once a company was attacked, Radar\/Dispossessor would then proactively contact company employees either through emails or phone calls, including links to video platforms showing videos of stolen data to turn up the heat, the agency said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This was always with the aim of increasing the blackmail pressure and increasing the willingness to pay,&#8221; the FBI said. Radar\/Dispossessor then used a separate leak page to set a countdown for public release of the victim data if organizations didn&#8217;t pay the ransom.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Patch Software and Protect Passwords\">Patch Software and Protect Passwords<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Radar\/Dispossessor joins a growing list of cybercriminal operations that have been <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/feds-snarl-alphv-blackcat-ransomware-operation\" rel=\"noopener\">disrupted<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> significantly or taken out indefinitely by global law-enforcement over the last several years, including the notorious ransomware gangs <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/global-law-enforcement-disrupts-lockbit-ransomware-gang\" rel=\"noopener\">LockBit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/alphv-blackcat-takedown-appears-to-be-law-enforcement-related\" rel=\"noopener\">ALPHV\/BlackCat,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as well as hacker forums such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/fbi-doj-shut-down-breachforums-launch-investigation\" rel=\"noopener\">BreachForums<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/fbi-seizes-genesis-cybercriminal-marketplace-operation-cookie-monster\" rel=\"noopener\">Genesis<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, most of these groups or forums end up resurfacing in some form or another, whether as a similar unit or allying with their former members in splinter cybercriminal gangs.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, though the shutdown of cybercriminal infrastructure comes as &#8220;great news,&#8221; it would be even better if there were warrants for the arrests of the gang&#8217;s leaders and if they were identified publicly, common notices that often accompany law-enforcement actions, noted Roger Grimes, data-driven defense evangelist at security awareness training firm KnowBe4. Thus as ransomware remains a prevalent threat, law-enforcement entities and security experts alike urge organizations to remain vigilant to protect themselves against attacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Given that initial entry often includes the abuse of software vulnerabilities and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/almost-half-of-former-employees-say-their-passwords-still-work\" rel=\"noopener\">weak passwords<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, every organization should ensure that they are frequently updating applications to their latest versions and applying any necessary fixes, as well as encouraging strong <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/singapore-banks-ditch-one-time-passwords\" rel=\"noopener\">password hygiene<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. These basic mitigations and protections are especially important for SMBs, which may not have the budgets to implement more robust and comprehensive protections.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The FBI has shut down dozens of servers associated with<\/p>\n","protected":false},"author":12,"featured_media":4838,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4837","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/fbi-shuts-down-dozens-of-radar-dispossessor-ransomware-servers.png?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4837"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4837\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4838"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4837"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}