viralamo

Menu
  • Technology
  • Science
  • Money
  • Culturs
  • Trending
  • Video

Subscribe To Our Website To Receive The Last Stories

Join Us Now For Free
Home
Technology
Why it’s hard to sanction ransomware groups
Technology

Why it’s hard to sanction ransomware groups

23/05/2022

A ransom message on a monochrome computer screen.

This story was originally published by ProPublica.

On February 25, the day after Russia invaded Ukraine, a prolific ransomware gang called Conti made a proclamation on its dark website. It was an unusually political statement for a cybercrime organization: Conti pledged its “full support of Russian government” and said it would use “all possible resources to strike back at the critical infrastructures” of Russia’s opponents.

Perhaps sensing that such a public alliance with the regime of Russian President Vladimir Putin could cause problems, Conti tempered its declaration later that day. “We do not ally with any government and we condemn the ongoing war,” it wrote in a follow-up statement that nonetheless vowed retaliation against the United States if it used cyberwarfare to target “any Russian-speaking region of the world.”

Conti was likely concerned about the specter of US sanctions, which Washington applies to people or countries threatening America’s security, foreign policy, or economy. But Conti’s attempt to resume its status as a stateless operation didn’t work out: Within days of Russia’s invasion, a researcher who would later tweet “Glory to Ukraine!” leaked 60,000 internal Conti messages on Twitter. The communications showed signs of connections between the gang and the FSB, a Russian intelligence agency, and included one suggesting a Conti boss “is in service of Pu.”

Yet even as Putin’s family and other Russian officials, oligarchs, banks, and businesses have faced an unprecedented wave of US sanctions designed to impose a crippling blow on the Russian economy, Conti was not hit with sanctions. Any time the US Treasury Department sanctions such an operation, Americans are legally barred from paying it ransom.

The fact that Conti wasn’t put on a sanctions list may seem surprising given the widespread damage it wrought. Conti penetrated the computer systems of more than 1,000 victims around the world, locked their files, and collected more than $150 million in ransoms to restore access. The group also stole victims’ data, published samples on a dark website, and threatened to publish more unless it was paid.

Advertisement

But only a small handful of the legions of alleged ransomware criminals and groups attacking US victims have been named on sanctions lists over the years by the Treasury Department’s Office of Foreign Assets Control, which administers and enforces them.

Putting a ransomware group on a sanctions list isn’t as simple as it might seem, current and former Treasury officials said. Sanctions are only as good as the evidence behind them. OFAC mostly relies on information from intelligence and law enforcement agencies, as well as media reports and other sources. When it comes to ransomware, OFAC has typically used evidence from criminal indictments, such as that of the alleged mastermind behind the Russia-based Evil Corp cybercrime gang in 2019. But such law enforcement actions can take years.

“Attribution is very difficult,” Michael Lieberman, assistant director of OFAC’s enforcement division, acknowledged at a conference this year. (The Treasury Department did not respond to ProPublica’s requests for comment.)

Ransomware groups are constantly changing their names, in part to evade sanctions and law enforcement. Indeed, on Thursday, a tech site called BleepingComputer reported that Conti itself has “officially shut down their operation.” The article, which cited information from a threat-prevention company called AdvIntel, laid out details about the status of Conti’s sites and servers but was unambiguous on a key point: “Conti’s gone, but the operation lives on.”

The evanescence of the Conti name underscores another reason it’s hard to sanction ransomware groups: Putting a group on a list of sanctioned entities without also naming the individuals behind it or releasing other identifying characteristics could cause hardship for bystanders. For example, a bank customer with the last name “Conti” might pop up as a sanctioned person, creating unintended legal exposure for that person and the bank, said Michael Parker, a former official in OFAC’s Enforcement Division. The government then would have to untangle these snarls.

Source link

Share
Tweet
Pinterest
Linkedin
Stumble
Google+
Email
Prev Article
Next Article

Related Articles

Facebook, Microsoft, and others launch Deepfake Detection Challenge
Deepfakes, or media that takes a person in an existing …

Facebook, Microsoft, and others launch Deepfake Detection Challenge

AI researchers say they created a better way to generate 3D photos
A group of AI researchers from Facebook, Virginia Tech, and …

AI researchers say they created a better way to generate 3D photos

Leave a Reply Cancel reply

Find us on Facebook

Related Posts

  • Elisa demos 5G remote vehicle controls and architectural 3D on phones
    Elisa demos 5G remote vehicle controls and …
    05/03/2020
  • TechCrunch’s Favorite Things of 2019
    Musicians pulled in $4.3M after Bandcamp waived …
    23/03/2020
  • 2020 will be a big year for online childcare — here are 7 startups to watch
    Apple buys edge-based AI startup Xnor.ai for …
    16/01/2020
  • Bravely Default II release delayed to February 26
    Bravely Default II release delayed to February …
    29/10/2020
  • Beat Saber is now an Oculus studio after Facebook acquisition
    Finally dark mode arrives to soothe your …
    03/03/2020

Popular Posts

  • 10 Unusual Things That Have Washed Ashore …
    18/06/2022 0
  • 10 Cockamamie Causes of Riots – Listverse
    21/05/2022 0
  • Top 10 Dumbest Products on Shark Tank …
    21/05/2022 0
  • 10 Things You May Not Know About …
    22/05/2022 0
  • 10 Real Historical Events That Inspired ‘Game …
    22/05/2022 0

viralamo

Pages

  • Contact Us
  • Privacy Policy
Copyright © 2022 viralamo
Theme by MyThemeShop.com

Ad Blocker Detected

Our website is made possible by displaying online advertisements to our visitors. Please consider supporting us by disabling your ad blocker.

Refresh