The LockBit ransomware operation is now recruiting affiliates and developers from the BlackCat/ALPHV and NoEscape after recent disruptions and exit scams.
Last week, the NoEscape and the BlackCat/ALPHV ransomware operation's Tor websites suddenly became inaccessible without warning.
Affiliates associated with NoEscape claimed that the ransomware operators pulled an exit scam, stealing millions of dollars in ransom payments and shutting off the operation's web panels and data leak sites.
NoEscape is believed to be a rebrand of the Avaddon ransomware operation, which shut down in June 201 and released their decryption keys to BleepingComputer.
We hope that NoEscape will once again release the decryption keys for their victims now that they have shut down their operation.
The BlackCat/ALPHV ransomware operation also suffered a 5-day disruption last week, with all their infrastructure going offline, including their data leak and negotiation sites.
On Monday, the ALPHV data leak site returned, but with all data removed.
BleepingComputer heard from multiple sources that a law enforcement operation was related to the outage.
As first reported by LeMagIT, LockBitSupp, the LockBit operation's manager, has begun to recruit affiliates from the BlackCat and NoEscape ransomware operations.
In posts to a Russian-speaking hacking forum, LockBitSupp told affiliates that if they have backups of the stolen data, they could use his data leak site and negotiation panel to continue to extort victims.
In addition to affiliates, LockBitSupp is trying to recruit the coder for the ALPHV encryptor.
While it is unclear if any of the BlackCat/NoEscape affiliates have moved over to LockBit, one BlackCat's victim has already been spotted on LockBit's data leak site.
BlackCat/ALPHV is a rebrand of the DarkSide and BlackMatter ransomware operations.
After BlackMatter's shutdown in November 2021, its affiliates transitioned to LockBit.
It is too soon to tell whether affiliates and penetration testers have lost trust in BlackCat or NoEscape and are moving to other operations.
Norton Healthcare discloses data breach after May ransomware attack.
ALPHV ransomware site outage rumored to be caused by law enforcement.
HTC Global Services confirms cyberattack after data leaked online.
Tipalti investigates claims of data stolen in ransomware attack.
Healthcare giant Henry Schein hit twice by BlackCat ransomware.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Wed, 13 Dec 2023 18:25:21 +0000