• Audio
  • Live tv
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of Service
Sunday, March 26, 2023
Morning News
No Result
View All Result
  • Login
  • Home
  • News
    • Local
    • National
    • World
  • Markets
  • Economy
  • Crypto
  • Real Estate
  • Sports
  • Entertainment
  • Health
  • Tech
    • Automotive
    • Business
    • Computer Sciences
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hi Tech & Innovation
    • Machine learning & AI
    • Security
    • Hardware
    • Internet
    • Robotics
    • Software
    • Telecom
  • Lifestyle
    • Fashion
    • Travel
    • Canadian immigration
  • App
    • audio
    • live tv
  • Home
  • News
    • Local
    • National
    • World
  • Markets
  • Economy
  • Crypto
  • Real Estate
  • Sports
  • Entertainment
  • Health
  • Tech
    • Automotive
    • Business
    • Computer Sciences
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hi Tech & Innovation
    • Machine learning & AI
    • Security
    • Hardware
    • Internet
    • Robotics
    • Software
    • Telecom
  • Lifestyle
    • Fashion
    • Travel
    • Canadian immigration
  • App
    • audio
    • live tv
No Result
View All Result
Morning News
No Result
View All Result
Home Tech Security

Hive ransomware: modern, efficient business model

by author
January 27, 2023
in Security
Reading Time: 5 mins read
0 0
A A
0
0
SHARES
14
VIEWS
Share on FacebookShare on TwitterLinkedinReddit
On the so-called dark web, providers of ransomware services and support pitch their products openly
On the so-called dark web, providers of ransomware services and support pitch their products openly.

The US Justice Department’s shutdown Thursday of the Hive ransomware operation—which extorted some $100 million from more than 1,500 victims worldwide—highlights how hacking has become an ultra-efficient, specialized industry that can allow anyone to become a cyber-shakedown artist.

Modern business model

Hive operated in what cybersecurity experts call a “ransomware as a service” style, or RaaS—a business that leases its software and methods to others to use in extorting a target.

The model is central to the larger ransomware ecosystem, in which actors specialize in one skill or function to maximize efficiency.

According to Ariel Ropek, director of cyber threat intelligence at cybersecurity firm Avertium, this structure makes it possible for criminals with minimal computer fluency to get into the ransomware game by paying others for their expertise.

“There are quite a few of them,” Ropek said of RaaS operations.

“It is really a business model nowadays,” he said.

How it works

On the so-called dark web, providers of ransomware services and support pitch their products openly.

At one end are the initial access brokers, who specialize in breaking into corporate or institutional computer systems.

They then sell that access to the hacker, or ransomware operator.

But the operator depends on RaaS developers like Hive, which have the programming skills to create the malware needed to carry out the operation and avoid counter-security measures.

The US Justice Department announced January 26, 2023 it had shut down the Hive ransomware operation, which had extorted more tha
The US Justice Department announced January 26, 2023 it had shut down the Hive ransomware operation, which had extorted more than $100 million from more than 1,500 victims worldwide.

Typically, their programs—once inserted by the ransomware operator into the target’s IT systems—are manipulated to freeze, via encryption, the target’s files and data.

The programs also extract the data back to the ransomware operator.

RaaS developers like Hive offer a full service to the operators, for a large share of the ransom paid out, said Ropek.

“Their goal is to make the ransomware operation as turnkey as possible,” he said.

Polite but firm

When the ransomware is planted and activated, the target receives a message telling them how to correspond and how much to pay to get their data unencrypted.

That ransom can run from thousands to millions of dollars, usually depending on the financial strength of the target.

Inevitably the target tries to negotiate on the portal. They often don’t get very far.

Menlo Security, a cybersecurity firm, last year published the conversation between a target and Hive’s “Sales Department” that took place on Hive’s special portal for victims.

In it, the Hive operator courteously and professionally offered to prove the decryption would work with a test file.

But when the target repeatedly offered a fraction of the $200,000 demanded, Hive was firm, insisting the target could afford the total amount.

Eventually, the Hive agent gave in and offered a significant reduction—but drew the line there.

FBI Director Christopher Wray with Deputy Attorney General Lisa Monaco (2L), and US Attorney General Merrick Garland (R), announ
FBI Director Christopher Wray with Deputy Attorney General Lisa Monaco (2L), and US Attorney General Merrick Garland (R), announce an international ransomware enforcement action against Hive on January 26, 2023.

“The price is $50,000. It’s final. What else to say?” the Hive agent wrote.

If a target organization refuses to pay, the RaaS developers hold a backup position: they threaten to release the hacked confidential files online or sell them.

Hive maintained a separate website, HiveLeaks, to publish the data.

On the back end of the deal, according to Ropek, there are specialist operations to collect the money, making sure those taking part get their shares of the ransom.

Others, known as cryptocurrency tumblers, help launder the ransom for the hacker to use above-ground.

Modest blow

Thursday’s action against Hive was only a modest blow against the RaaS industry.

There are numerous other ransomware specialists similar to Hive still operating.

The biggest current threat is LockBit, which attacked Britain’s Royal Mail in early January and a Canadian children’s hospital in December.

In November, the Justice Department said LockBit had reaped tens of millions of dollars in ransoms from 1,000 victims.

And it isn’t hard for Hive’s operators to just start again.

“It’s a relatively simple process of setting up new servers, generating new encryption keys. Usually there’s some kind of rebrand,” said Ropek.

© 2023 AFP

Citation:
Hive ransomware: modern, efficient business model (2023, January 27)
retrieved 27 January 2023
from https://techxplore.com/news/2023-01-hive-ransomware-modern-efficient-business.html
This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.
Previous Post

Hong Kong to ban CBD, label it a ‘dangerous drug’

Next Post

Madison Square Garden’s facial recognition blacklisting sparks outcry

Related Posts

Computer Sciences

US Census data vulnerable to attack without enhanced privacy measures, shows study

March 23, 2023
11
Security

Satellite data: The other type of smartphone data you might not know about

March 21, 2023
11
Next Post

Madison Square Garden's facial recognition blacklisting sparks outcry

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

POPULAR TODAY

National

2 dead, 9 injured after vehicle strikes pedestrians in Quebec’s Lower St. Lawrence region

by author
March 25, 2023
0
12

Two people are dead and nine injured after a pickup truck hit several pedestrians in downtown Amqui on Monday in...

B.C. widow finds unexpected love while performing in blind choir

March 25, 2023
12

How a small town Canadian grandmother ended up in a Hong Kong prison

March 26, 2023
12

Suspect in Amqui, Que. pedestrian deaths charged; police identify victims

March 26, 2023
12
Austin, Texas

The 10 Best (and Worst) U.S. Cities for Sleep

March 26, 2023
12

POPULAR NEWS

Why Ray Dalio says SVB collapse is a ‘canary in the coal mine’

March 21, 2023
20

Biden backs tax hike on investment income to bolster Medicare, as he rolls out his budget proposal

March 20, 2023
19

Hackers scored data center logins for big corporations more than a year ago. Now they’re selling that information

March 21, 2023
16
A woman holds out her hands to a physician.

Osteoarthritis: Experimental Drug May Help Reduce Inflammation and Symtpoms, Early Study Finds

March 23, 2023
16

A new way to trap radioactive waste in minerals for long-term storage

March 21, 2023
15

EDITOR'S PICK

Bitcoin core dev calls out ‘misleading’ auction selling his code as an NFT
Crypto

Bitcoin core dev calls out ‘misleading’ auction selling his code as an NFT

by author
March 8, 2023
0
11

One of the original core developers behind Bitcoin (BTC), Luke Dashjr, has taken to social media to call out an...

Read more

Businesses expect slower sales in short term as cost, labour issues persist: survey

What You Can Do Before Daylight Saving Time to Help Your Body Adjust

Why This FDA-Approved Drug for Pre-Term Birth is being Pulled From the Market

Vancouver snowplow gets stuck in ditch during storm

Morning News

Welcome to our Ads

Create ads focused on the objectives most important to your business Please contact us info@morns.ca

  • Home
  • Audio
  • Live tv
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of Service

© 2022 Morning News - morns.ca by morns.ca.

No Result
View All Result
  • Home
  • News
    • Local
    • National
    • World
  • Markets
  • Economy
  • Crypto
  • Real Estate
  • Sports
  • Entertainment
  • Health
  • Tech
    • Automotive
    • Business
    • Computer Sciences
    • Consumer & Gadgets
    • Electronics & Semiconductors
    • Energy & Green Tech
    • Engineering
    • Hi Tech & Innovation
    • Machine learning & AI
    • Security
    • Hardware
    • Internet
    • Robotics
    • Software
    • Telecom
  • Lifestyle
    • Fashion
    • Travel
    • Canadian immigration
  • App
    • audio
    • live tv
  • Login

© 2022 Morning News - morns.ca by morns.ca.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Go to mobile version