The U.S. State Department is offering rewards of up to $10 million for information that could lead to the identification or location of ALPHV/Blackcat ransomware gang leaders.
An additional $5 million bounty is also available for tips on individuals trying to take part in ALPHV ransomware attacks, likely to discourage affiliates and initial access brokers.
The FBI linked this ransomware gang to over 60 breaches worldwide during its first four months of activity between November 2021 and March 2022.
These rewards are provided through the U.S. Transnational Organized Crime Rewards Program, with more than $135 million paid for helpful tips since 1986.
The State Department has set up a dedicated Tor SecureDrop server that can be used to submit tips on ALPHV and other wanted threat actors.
ALPHV surfaced in November 2021 and is believed to be a rebrand of the DarkSide and BlackMatter ransomware operations.
The operation shut down in May 2021 after extensive investigations by law enforcement led to the seizure of their infrastructure following the Colonial Pipeline attack.
The gang re-emerged under the BlackMatter brand, shut down again in November 2021, and returned as ALPHV/BlackCat in February 2022.
ALPHV also recently claimed another pipeline attack against Canada's Trans-Northern Pipelines, which is now investigating these claims after confirming a November 2023 network breach.
In January, the U.S. government also announced rewards of up to $10 million for information on the leaders of the Hive ransomware gang.
The State Department previously announced bounties of up to $15 million for tips on members and affiliates of the Hive, Clop, Conti [1, 2], REvil, and Darkside ransomware operations.
Trans-Northern Pipelines investigating ALPHV ransomware attack claims.
New RustDoor macOS malware impersonates Visual Studio update.
MGM Resorts ransomware attack led to $100 million loss, data theft.
Fidelity National Financial: Hackers stole data of 1.3 million people.
MGM casino's ESXi servers allegedly encrypted in ransomware attack.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Thu, 15 Feb 2024 19:00:22 +0000