International Cooperation Takes Down Multi-Million Euro HIVE Ransomware Scheme

International Cooperation Takes Down Multi-Million Euro HIVE Ransomware Scheme

Law enforcement authorities from Germany, the Netherlands, and the US, supported by Europol, have dismantled the infrastructure of HIVE ransomware, a notorious cybercrime group responsible for encrypting the data and computer systems of large IT and oil companies in the EU and the USA. The international operation, which involved 13 countries, led to the identification of decryption keys that were shared with many victims, enabling them to regain access to their data without paying the cybercriminals. The HIVE associates executed the cyberattacks, while developers created, maintained and updated the HIVE ransomware. The cybercriminals used the double extortion model of “ransomware-as-a-service,” where they copied the data and encrypted the files, then demanded a ransom to decrypt the files and prevent the stolen data from being published on the Hive Leak Site. The group has targeted a range of businesses, government facilities, telecommunications, manufacturing, IT, healthcare, and public health since June 2021, with victims in over 80 countries worldwide losing almost EUR 100 million in ransom payments.

The successful operation prevented the payment of more than USD 130 million or the equivalent of about EUR 120 million of ransom payments, and Europol played a key role in facilitating information exchange, coordinating the operation, and funding operational meetings in Portugal and the Netherlands. Europol also provided analytical support, linked available data to various criminal cases within and outside the EU, and supported the investigation through cryptocurrency, malware, decryption, and forensic analysis. The Joint Cybercrime Action Taskforce (J-CAT) at Europol, consisting of cybercrime liaison officers from different countries, worked on high-profile cybercrime investigations and supported the operation.

Online shopping fraud – a winter tale that always ends with fraudsters behind bars

Europol building

A coordinated crackdown on e-commerce fraud has seen 59 scammers arrested and new investigative leads triggered all across Europe as part of the 2022 e-Commerce Action (eComm 2022). 

The month-long (1-31 October 2022) operation saw 19 countries take part in this clampdown on the criminal networks using stolen credit card information to order high-value goods from online shops.  

The action was coordinated by Europol’s European Cybercrime Centre (EC3) and the Merchant Risk Council. It received the direct assistance from merchants, logistic companies, banks and payment card schemes. 

After several months of preparation, law enforcement authorities in participating countries raided the locations where illegally purchased goods had been delivered, arresting the suspects and confiscating the fraudulently purchased goods. Evidence was built to support the cases all the way to prosecuting the suspects. Investigations are still ongoing in various countries, with more arrests expected in the coming weeks.

Participating countries

Albania, Austria, Bosnia-Herzegovina, Colombia, Czech Republic, Finland, France, Georgia, Germany, Greece, Hungary, Latvia, Poland, Portugal, Romania, Slovak Republic, Spain, Sweden and United Kingdom.

Changing attack vectors

Even if payments online are generally very secure, mostly thanks to Secure Customer Authentication (SCA) methods widely implemented in Europe, criminals are continuously altering their techniques to unlock new ways of stealing money. 
The findings of eComm 2022 have identified the following key threats to the e-commerce sector: 

  • Phishing, vishing and smishing fraud: Stolen credit card numbers are often obtained through phishing/vishing/smishing attacks whereby criminals contact people by phone, text messages, messaging apps or email and attempt to convince them to hand over their credit card information. Sometimes these attacks promise a reward, other times they impersonate a trusted business or a government agency.
  • Account takeover fraud: This fraud occurs when a criminal gains access to a user’s account on an ecommerce store. This can be achieved through a variety of methods, including purchasing stolen passwords, security codes, or personal information on the dark web or successfully implementing a phishing scheme against a particular customer. Once they have gained access to a user’s account, criminals can engage in fraudulent activity. For instance, they can change the details of a user’s account, make purchases on ecommerce stores, can withdraw funds, and can even gain access to other accounts for this user.
  • Triangulation fraud: This type of fraud happens when online criminals set up a fake or replica website and entice buyers with cheap goods. Sometimes these fake websites may appear in ads, or be sent to a user’s email directing to the website through a phishing attempt. The catch is that these goods don’t actually exist, or of course are never shipped.

How to fight back against e-commerce fraud

Through an awareness campaign launching today, law enforcement across Europe are teaming up with Europol and the Merchant Risk Council to share practical advice on how to outwit criminals trying to abuse the online shopping experience. 

The aim of the campaign is to make e-commerce more secure by promoting safe online purchasing methods and by helping new merchants to open their online shop without the risk of cyberattacks.

Participating countries and partners will promote the campaign through their social media channels using the #SellSafe hashtag to help merchants understand the risks of e-commerce fraud.

Tips to protect your e-business:

  • Ensure all your employees are aware of the fraud issues affecting online stores.
  • Stay up to date on the types of payment fraud affecting businesses and have the tools in place to prevent them. Your national payments organisation will have details on payment fraud types.
  • Get to know your customers in order to be able to verify their payments.

Tips for online shoppers:

  • Never send your card number, PIN or any other card information to anyone by e-mail.
  • Never send money to anyone you don’t know.
  • Always save all documents related to your online purchases.
  • If you are not buying anything, don’t submit your card details.
  • Check your online banking service regularly. Notify your bank immediately if you see payments or withdrawals that you have not made yourself.

World’s most dangerous malware EMOTET disrupted through global action

Europol building

Law enforcement and judicial authorities worldwide have this week disrupted one of most significant botnets of the past decade: EMOTET. Investigators have now taken control of its infrastructure in an international coordinated action.

This operation is the result of a collaborative effort between authorities in the Netherlands, Germany, the United States, the United Kingdom, France, Lithuania, Canada and Ukraine, with international activity coordinated by Europol and Eurojust. This operation was carried out in the framework of the European Multidisciplinary Platform Against Criminal Threats (EMPACT).

EMOTET has been one of the most professional and long lasting cybercrime services out there. First discovered as a banking Trojan in 2014, the malware evolved into the go-to solution for cybercriminals over the years. The EMOTET infrastructure essentially acted as a primary door opener for computer systems on a global scale. Once this unauthorised access was established, these were sold to other top-level criminal groups to deploy further illicit activities such data theft and extortion through ransomware.

Spread via Word documents

The EMOTET group managed to take email as an attack vector to a next level. Through a fully automated process, EMOTET malware was delivered to the victims’ computers via infected e-mail attachments.  A variety of different lures were used to trick unsuspecting users into opening these malicious attachments. In the past, EMOTET email campaigns have also been presented as invoices, shipping notices and information about COVID-19.

All these emails contained malicious Word documents, either attached to the email itself or downloadable by clicking on a link within the email itself. Once a user opened one of these documents, they could be prompted to “enable macros” so that the malicious code hidden in the Word file could run and install EMOTET malware on a victim’s computer.

Attacks for hire

EMOTET was much more than just a malware. What made EMOTET so dangerous is that the malware was offered for hire to other cybercriminals to install other types of malware, such as banking Trojans or ransomwares, onto a victim’s computer.

This type of attack is called a ‘loader’ operation, and EMOTET is said to be one of the biggest players in the cybercrime world as other malware operators like TrickBot and Ryuk have benefited from it.

Its unique way of infecting networks by spreading the threat laterally after gaining access to just a few devices in the network made it one of the most resilient malware in the wild.

Disruption of EMOTET’s infrastructure

The infrastructure that was used by EMOTET involved several hundreds of servers located across the world, all of these having different functionalities in order to manage the computers of the infected victims, to spread to new ones, to serve other criminal groups, and to ultimately make the network more resilient against takedown attempts.

To severely disrupt the EMOTET infrastructure, law enforcement teamed up together to create an effective operational strategy. It resulted in this week’s action whereby law enforcement and judicial authorities gained control of the infrastructure and took it down from the inside. The infected machines of victims have been redirected towards this law enforcement-controlled infrastructure.  This is a unique and new approach to effectively disrupt the activities of the facilitators of cybercrime.

How to protect oneself against loaders

Many botnets like EMOTET are polymorphic in nature. This means that the malware changes its code each time it is called up. Since many antivirus programmes scan the computer for known malware codes, a code change may cause difficulties for its detection, allowing the infection to go initially undetected.

A combination of both updated cybersecurity tools (antivirus and operating systems) and cybersecurity awareness is essential to avoid falling victim to sophisticated botnets like EMOTET. Users should carefully check their email and avoid opening messages and especially attachments from unknown senders. If a message seems too good to be true, it likely is and emails that implore a sense of urgency should be avoided at all costs.

As part of the criminal investigation conducted by the Dutch National Police into EMOTET, a database containing e-mail addresses, usernames and passwords stolen by EMOTET was discovered. You can check if your e-mail address has been compromised.  As part of the global remediation strategy, in order to initiate the notification of those affected and the cleaning up of the systems, information was distributed worldwide via the network of so-called Computer Emergency Response Teams (CERTs).

EMOTET

The following authorities took part in this operation:

  • Netherlands: National Police (Politie), National Public Prosecution Office (Landelijk Parket)
  • Germany: Federal Criminal Police (Bundeskriminalamt), General Public Prosecutor’s Office Frankfurt/Main (Generalstaatsanwaltschaft)
  • France: National Police (Police Nationale), Judicial Court of Paris (Tribunal Judiciaire de Paris)
  • Lithuania: Lithuanian Criminal Police Bureau (Lietuvos kriminalinės policijos biuras), Prosecutor’s General’s Office of Lithuania
  • Canada: Royal Canadian Mounted Police
  • United States: Federal Bureau of Investigation, U.S. Department of Justice, US Attorney’s Office for the Middle District of North Carolina
  • United Kingdom: National Crime Agency, Crown Prosecution Service 
  • Ukraine: National Police of Ukraine (Національна поліція України), of the Prosecutor General’s Office (Офіс Генерального прокурора).

Hit by ransomware? No More Ransom now offers 136 free tools to rescue your files

No more ransom

As the initiative turns six, over 10 million people have downloaded the decryption tools

Ransomware attacks have been growing in number and severity for years, with headlines focused on ransom demands that have climbed to amounts once unthinkable. While the data is alarming, it does not mean that you are helpless against the high-tech extortionists orchestrating these attacks. The No More Ransom initiative offers over a hundred free decryption tools to rescue your hostage files. 

Six years of public-private partnership

Celebrating its sixth anniversary today, No More Ransom provides keys to unlocking encrypted files as well as information on how to avoid getting infected in the first place.

Launched by Europol, the Dutch National Police (Politie) and IT security companies, the No More Ransom portal initially offered four tools for unlocking different types of ransomware and was available only in English.

Six years later, No More Ransom offers 136 free tools for 165 ransomware variants, including Gandcrab, REvil/Sodinokibi, Maze/Egregor/Sekhmet and more. Over 188 partners from the public and private sector have joined the scheme, regularly providing new decryption tools for the latest strains of malicious software.  

To date, the scheme has so far helped over 1.5 million people successfully decrypt their devices without needing to pay the criminals. The portal is available in 37 languages in order to better assist victims of ransomware across the globe.

No better cure than prevention

The best cure against ransomware remains diligent prevention. You are strongly advised to:

  • Regularly back up data stored on your electronic devices.
  • Watch your clicks – do you know where a link will take you?
  • Do not open attachments in e-mails from unknown senders, even if they look important and credible.
  • Ensure that your security software and operating system are up to date.
  • Use two-factor authentication (2FA) to protect your user accounts.
  • Limit the possibility to export large amounts of corporate data to external file exchange portals.
  • If you become a victim, do not pay! Report the crime and check No More Ransom for decryption tools.

Join the fight against ransomware

Are you a cybersecurity company willing to join forces with law enforcement and industry leaders in the fight to disrupt ransomware?

Do you have an innovative solution for ransomware families not covered yet in the portal to help victims recover their files without giving into the demands of the criminals?

Then we want to hear from you!

Find more information and prevention tips on www.nomoreransom.org 

Bargain or Dealbreaker?

Safe Sales, Safe Revenue

Bargain or Dealbreaker?

  1. Buy from trusted sources.
    Use brands and shops that you are familiar with.
  2. Check reviews and ratings.
    Especially of unknown stores and individual sellers.
  3. Control recurring charges.
    Before providing your card details to pay a continuous service over the internet, find out how you can stop that service.
  4. Make sure the data transfer is secure.
    Use HTTPS and SSL protocols when browsing the internet. Remember, the padlock symbol alone doesn’t make a website legitimate.
  5. Think twice before purchasing.
    Make sure you understand the risks of buying online.
  6. Use credit cards when purchasing things online.
    Most credit cards have a strong customer protection policy. If you don’t get what you ordered, the card issuer will refund you.
  7. Save all documents related to your online purchases.
    They may be needed to establish the terms and conditions of the sale or to prove that you have paid for the goods.
  8. Don’t send money to someone you don’t know.
    If you wouldn’t give money to a random person on the street, don’t do it on the internet. If possible, reserve the right to receive goods first.
  9. Never send your card details by email.
    Never send a copy of your card, your card number, PIN or any other card information to anyone by email.
  10. Not buying? Don’t leave your card behind.
    If you are not buying anything, don’t submit or save your card details.
  11. Check the website payment security.
    Only do your online shopping on websites that use full authentication systems (such as Verified by Visa / Mastercard Secure Code).
#BuySafePaySafe