{"id":125139,"date":"2021-05-14T23:23:51","date_gmt":"2021-05-14T23:23:51","guid":{"rendered":"https:\/\/precoinnews.com\/?p=125139"},"modified":"2021-05-14T23:23:51","modified_gmt":"2021-05-14T23:23:51","slug":"darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down","status":"publish","type":"post","link":"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/","title":{"rendered":"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down"},"content":{"rendered":"

The criminal hacking group DarkSide, which the F.B.I. has blamed for carrying out a ransomware attack that crippled fuel delivery across the Southeastern United States this week, has announced that it is shutting down because of unspecified \u201cpressure\u201d from the United States.<\/p>\n

In a statement written in Russian and provided to The New York Times on Friday by the cybersecurity firm Intel 471, DarkSide said it had lost access to the public-facing portion of its online system, including its blog and payment server, as well as funds that it said had been withdrawn to an unknown account. It said the group\u2019s main web page and other public-facing resources would go offline within 48 hours.<\/p>\n

\u201cDue to the pressure from the U.S., the affiliate program is closed,\u201d the statement said, referring to intermediary hackers, the so-called affiliates, it works with to break into corporate computer systems. \u201cStay safe and good luck.\u201d<\/p>\n

What that pressure may have been is unclear, but on Thursday, President Biden said the United States would not rule out a retaliatory strike against DarkSide that would \u201cdisrupt their ability to operate.\u201d The White House spokeswoman, Jen Psaki, said the administration was waiting for recommendations from U.S. Cyber Command, but government officials on Friday declined to comment further about whether any action had been taken.<\/p>\n

Cybersecurity analysts cautioned that the DarkSide statement could be a ruse, allowing its members to regroup and deflect the negative attention caused by the attack. The group\u2019s announcement was reported earlier by The Wall Street Journal.<\/p>\n

The crisis began when Colonial Pipeline, the operator of one of the nation\u2019s largest fuel pipelines, announced on May 7 that it had been hit with a ransomware attack, in which criminal groups lock up computer systems and hold data hostage until the victim pays a ransom. In response, the company protectively shut down its pipeline, which delivers nearly half of the jet fuel and gasoline used on the Atlantic Coast, disrupting air travel and causing drivers to descend on gas stations in a surge of panic buying.<\/p>\n

To free up its computer systems, Colonial Pipeline paid the extortionists about 75 Bitcoin, or nearly $5 million, according to people briefed on the transaction. The decision allowed the company to get gas flowing again, but may have complicated the Biden administration\u2019s efforts to stave off new attacks.<\/p>\n

In a statement on Friday, a Colonial spokeswoman said, \u201cThere is an ongoing investigation, and we\u2019re not commenting on the ransom.\u201d<\/p>\n

Elliptic, a computer security company specializing in cryptocurrency, said on Friday that it had identified the Bitcoin wallet used by DarkSide to collect the Colonial Pipeline ransom payment. In a statement, Elliptic said Colonial Pipeline sent the ransom payment to DarkSide last Saturday.<\/p>\n

Since the DarkSide account was opened in March, Elliptic said, it had received $17.5 million from 21 Bitcoin wallets, indicating the number of ransoms it had collected just this spring. Cybersecurity analysts assess that the group has been active since at least August, and has most likely used a number of different Bitcoin wallets to receive ransoms.<\/p>\n

The intense scrutiny that followed the Colonial Pipeline attack has clearly unsettled ransomware groups. This week, the operators behind two major Russian-language ransomware platforms, REvil and Avaddon, announced strict new rules governing the use of their products, including bans on targeting government-affiliated entities, hospitals or educational institutions.<\/p>\n

The administrator of XSS, a popular Russian-language cybercrime forum, announced an immediate ban on all ransomware activity on the forum, citing, among other things, the bad press associated with the industry. In a statement posted in the forum, the administrator called the attention a \u201ccritical mass of harm, nonsense, hype and noise,\u201d saying even the spokesman for President Vladimir V. Putin of Russia had weighed in on the Colonial Pipe attack. (The spokesman, Dmitri S. Peskov, denied that the Kremlin had been involved in the attack on the pipeline.)<\/p>\n

\u201cThe word ransom has become associated with a whole series of unpleasant things \u2014 geopolitics, blackmail, government cyberattacks,\u201d the XSS administrator wrote. \u201cThis word has become dangerous and toxic.\u201d<\/p>\n

Even if DarkSide has shut down, the threat from ransomware has not passed. Cybercriminal networks often disband, regroup and rebrand themselves in an effort to throw off law enforcement, cybersecurity experts say.<\/p>\n

\u201cIt\u2019s likely that these ransomware operators are trying to retreat from the spotlight more than suddenly discovering the error of their ways,\u201d said Mark Arena, Intel 471\u2019s chief executive. \u201cA number of the operators will most likely continue to operate in their own close-knit groups, resurfacing under different aliases and ransomware names.\u201d<\/p>\n

Indeed, DarkSide gave no indication that its members were getting out of the ransomware business or even letting victims currently infected with the group\u2019s malware off the hook. In its statement, DarkSide said it would hand over its decryption tools to affiliates, giving these intermediaries, who were responsible for infecting computer systems with the group\u2019s malicious software, the ability to negotiate ransoms with victims directly.<\/p>\n

\u201cYou will be given decryption tools for all the companies that haven\u2019t paid yet,\u201d the statement read. \u201cAfter that, you will be free to communicate with them wherever you want in any way you want.\u201d<\/p>\n

Julian Barnes contributed reporting.<\/p>\n

Source: Read Full Article<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"

The criminal hacking group DarkSide, which the<\/p>\n","protected":false},"author":3,"featured_media":125138,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23051],"tags":[],"yoast_head":"\nDarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down - Pre Coin News<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down - Pre Coin News\" \/>\n<meta property=\"og:description\" content=\"The criminal hacking group DarkSide, which the\" \/>\n<meta property=\"og:url\" content=\"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/\" \/>\n<meta property=\"og:site_name\" content=\"Pre Coin News\" \/>\n<meta property=\"article:published_time\" content=\"2021-05-14T23:23:51+00:00\" \/>\n<meta name=\"author\" content=\"mediabest\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/precoinnews.com\/wp-content\/uploads\/2021\/05\/DarkSide-Blamed-for-Gas-Pipeline-Attack-Says-It-Is-Shutting-Down.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"mediabest\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/\",\"url\":\"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/\",\"name\":\"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down - Pre Coin News\",\"isPartOf\":{\"@id\":\"https:\/\/precoinnews.com\/#website\"},\"datePublished\":\"2021-05-14T23:23:51+00:00\",\"dateModified\":\"2021-05-14T23:23:51+00:00\",\"author\":{\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a\"},\"breadcrumb\":{\"@id\":\"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/precoinnews.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Business\",\"item\":\"https:\/\/precoinnews.com\/category\/business\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/precoinnews.com\/#website\",\"url\":\"https:\/\/precoinnews.com\/\",\"name\":\"Pre Coin News\",\"description\":\"precoinnews.com\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/precoinnews.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a\",\"name\":\"mediabest\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/precoinnews.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g\",\"caption\":\"mediabest\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down - Pre Coin News","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/","og_locale":"en_US","og_type":"article","og_title":"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down - Pre Coin News","og_description":"The criminal hacking group DarkSide, which the","og_url":"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/","og_site_name":"Pre Coin News","article_published_time":"2021-05-14T23:23:51+00:00","author":"mediabest","twitter_card":"summary_large_image","twitter_image":"https:\/\/precoinnews.com\/wp-content\/uploads\/2021\/05\/DarkSide-Blamed-for-Gas-Pipeline-Attack-Says-It-Is-Shutting-Down.jpg","twitter_misc":{"Written by":"mediabest","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/","url":"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/","name":"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down - Pre Coin News","isPartOf":{"@id":"https:\/\/precoinnews.com\/#website"},"datePublished":"2021-05-14T23:23:51+00:00","dateModified":"2021-05-14T23:23:51+00:00","author":{"@id":"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a"},"breadcrumb":{"@id":"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/precoinnews.com\/business\/darkside-blamed-for-gas-pipeline-attack-says-it-is-shutting-down\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/precoinnews.com\/"},{"@type":"ListItem","position":2,"name":"Business","item":"https:\/\/precoinnews.com\/category\/business\/"},{"@type":"ListItem","position":3,"name":"DarkSide, Blamed for Gas Pipeline Attack, Says It Is Shutting Down"}]},{"@type":"WebSite","@id":"https:\/\/precoinnews.com\/#website","url":"https:\/\/precoinnews.com\/","name":"Pre Coin News","description":"precoinnews.com","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/precoinnews.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/precoinnews.com\/#\/schema\/person\/ad0e9920e03d3b41c7ad02a18375d76a","name":"mediabest","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/precoinnews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f5f13cb3b94fc348d515c0951f6ca073?s=96&d=mm&r=g","caption":"mediabest"}}]}},"_links":{"self":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts\/125139"}],"collection":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/comments?post=125139"}],"version-history":[{"count":0,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/posts\/125139\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/media\/125138"}],"wp:attachment":[{"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/media?parent=125139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/categories?post=125139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/precoinnews.com\/wp-json\/wp\/v2\/tags?post=125139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}