A law enforcement operation is rumored to be behind an outage affecting ALPHV ransomware gang's websites over the last 30 hours.
The ALPHV negotiation and data leak sites suddenly became unavailable yesterday and continue to remain down today.
BleepingComputer has also confirmed that unique Tor negotiation URLs shared with victims in ransom notes are also down, indicating a disruption to the ransomware gang's public-facing infrastructure and a halt to ongoing negotiations.
The Tox status for the Admin claims that the operation is repairing their servers but they have not answered questions about what happened.
BleepingComputer suspects that the ransomware gang may have suffered potential law enforcement action after their recent activities, which was also hinted at by others.
When the FBI breached REvil's servers, they obtained the decryption keys for the victims of the Kaseya ransomware attack.
BleepingComputer contacted the FBI about the ALPHV website disruption, but a reply was not immediately available.
The ALPHV/BlackCat ransomware operation is believed to be a rebrand of the DarkSide gang.
The operation launched in 2020 and quickly rose to prominence over the next year.
After attacking the Colonial Pipeline, the ransomware gang faced intense scrutiny by the US government and international law enforcement, ultimately leading to the seizure of their infrastructure and the operation shutting down.
Only a few months later, the ransomware gang returned, this time under the name BlackMatter.
The managers of this operation claimed in an interview that they were affiliates of the DarkSide operation and not the original leaders.
Only a short four months later, BlackMatter shut down its operation in November 2021 after claiming to be under pressure from law enforcement.
In February 2022, the ransomware gang returned again, this time under the name ALPHV, also known as BlackCat, for an image used on their Tor negotiation sites.
While this rebrand started out like most ransomware gangs, targeting companies in extortion attacks worldwide, they have expanded their operations by partnering with English-speaking affiliates and targeting critical infrastructure, such as hospitals and water suppliers.
Due to this, it was only a matter of time until they again felt the scrutiny of law enforcement, whether it be this disruption or a future one.
Ragnar Locker ransomware's dark web extortion sites seized by police.
Tipalti investigates claims of data stolen in ransomware attack.
Healthcare giant Henry Schein hit twice by BlackCat ransomware.
MGM casino's ESXi servers allegedly encrypted in ransomware attack.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Fri, 08 Dec 2023 18:35:19 +0000