cover of episode 126: REvil

126: REvil

2022/10/18
logo of podcast Darknet Diaries

Darknet Diaries

AI Deep Dive AI Chapters Transcript
People
J
Jack Recider
Topics
Jack Recider: 我讲述了一个发生在美国的诈骗故事,一个巴西人及其同伙利用虚假身份信息注册网约车和外卖送餐账号,并倒卖这些账号牟利。他们利用互联网上的信息轻易获取他人身份信息,并通过洗钱的方式掩盖非法所得。最终,他们因身份盗窃和洗钱罪被判处两年监禁。这个故事反映了互联网暗网中存在的各种诈骗活动,以及犯罪分子利用信息技术进行犯罪的狡猾手段。 这个故事也提醒我们,网络安全的重要性日益凸显,个人信息保护和反洗钱措施的加强刻不容缓。我们需要提高警惕,避免成为网络犯罪的受害者。同时,执法部门也需要加强合作,打击网络犯罪活动,维护网络安全环境。 Will: 我详细分析了REvil勒索软件及其背后的犯罪团伙的活动。REvil起源于GandCrab勒索软件,该团伙率先采用了“大型猎物”的攻击策略,专门针对大型企业和机构进行攻击,以获取巨额赎金。REvil不仅是一种勒索软件,更是一种“勒索软件即服务”(RaaS)平台,允许其他犯罪分子付费使用该软件进行攻击,并从中分成。 REvil团伙利用公开信息(OSINT)收集目标公司信息,通过购买或自行获取网络访问权限,然后部署勒索软件进行攻击。他们不仅加密受害者的数据,还威胁泄露数据,甚至实施DDoS攻击,以迫使受害者支付赎金。REvil团伙的攻击目标涵盖了政府机构、企业、甚至关键基础设施,造成了巨大的经济损失和社会影响。 最终,在执法部门的联合行动下,REvil团伙的主要成员被逮捕,其服务器也被关闭,REvil的活动也随之停止。然而,REvil的兴衰也反映了网络犯罪的复杂性和持续性,新的勒索软件和犯罪团伙不断涌现,网络安全威胁依然严峻。

Deep Dive

Chapters
Gustavo, a Brazilian tourist in the US, devised a scheme to create and sell fake driver accounts for ride-sharing and food delivery apps using stolen identities. He and four accomplices generated over 100 fraudulent accounts before being arrested and sentenced to two years in prison for identity theft and money laundering.
  • Brazilian tourist in the US
  • Created and sold fake driver accounts for ride-sharing and food delivery apps
  • Used stolen identities
  • Over 100 fraudulent accounts
  • Arrested and sentenced to two years in prison

Shownotes Transcript

REvil is the name of a ransomware service as well as a group of criminals inflicting ransomware onto the world. Hear how this ransomware shook the world.

A special thanks to our guest Will, a CTI researcher with Equinix.

Sponsors

Support for this show comes from Zscalar. Zscalar zero trust exchange will scrutinize the traffic and permit or deny traffic based on a set of rules. This is so much more secure than letting data flow freely internally. And it really does mitigate ransomware outbreaks. The Zscaler Zero Trust Exchange gives YOU confidence in your security to feel empowered to focus on other parts of your business, like digital transformation, growth, and innovation. Check out the product at zscaler.com.

Support for this show comes from Arctic Wolf. Arctic Wolf is the industry leader in security operations solutions, delivering 24x7 monitoring, assessment, and response through our patented Concierge Security model. They work with your existing tools and become an extension of your existing IT team. Visit arcticwolf.com/darknet to learn more.