Uh-oh, Russian Cyber-Muppets Break the Golden Rule
Even the notorious ransomware baddies can make silly errors, and this instance was a major blunder. They almost booked themselves a stay in a Russian gulag. How did it happen? By unintentionally infecting a firm in the Commonwealth of Independent States (CIS). Dominic Alvieri, a leading threat-hunter, labeled this the “dunce of the day”. The Nova team, associated with ransomware group RAlord, had to beg Eriell Group, a significant oilfield services provider headquartered in Uzbekistan with an office in Moscow, for forgiveness.
Nova’s ‘Whoops’ Incident
Eriell reached out to Nova to highlight an affiliate’s mistake. That individual has since been removed from the operation. Nova extended a “formal apology” and even vowed to assist Eriell in recovering, free of charge. They asserted that they did not encrypt any documents and will not be disclosing any stolen information.
Rule One: Avoid CIS Targets
“The primary rule of ransomware club: never target CIS organizations,” remarked Allan Liska, a threat intelligence expert at GadgetLad. While technically against the law, cybercrime in Russia and other CIS nations often goes unnoticed unless local businesses are affected. Certain groups, such as DragonForce, VanHelsing, and the notorious LockBit, adhere to a policy of avoiding Russian and CIS firms. Nova’s blundering companion won’t be accepted in these circles anytime soon.
Not the Only Buffoons in the Field
This isn’t the first occasion these cyber goofballs have caused chaos. Previously, the Scattered Lapsus$ Hunters boasted about infiltrating Resecurity’s systems. In a surprising turn, they stumbled into a honeypot, resulting in one of them receiving a subpoena. Then there were CyberVolk, the pro-Russian hacktivists who made a blunder by hardcoding master keys into their programs. Victims were able to retrieve their data at no cost.
When Code Goes Haywire
Another mishap came from Sicarii developers, who botched their encryptor code. Their tool created a new cryptographic key pair each time, but then discarded the private key, rendering victims without a master key to access their files. Similarly, an error in Nitrogen ransomware’s code means their decryptor is incapable of retrieving files, making payments pointless. What a way to shoot oneself in the foot.
Mocking the Villains
John Fokker from Trellix expressed his frustration with the security community “elevating threat actors” that he and his team initiated the Dark Web Roast, poking fun at these digital wrongdoers. “They’re simply individuals behind computers trying to steal your data and make some cash,” Fokker stated to GadgetLad. “They’re not heroes or anything. They blunder just like everyone else, providing us with true belly laughs.”
Conclusion: When Villains Act Completely Foolish
Even the so-called cyber geniuses have their clueless moments, leaving us with some unforgettable amusement. The next time you hear about ransomware, remember: they are just as human as the rest of us, with all the same potential for foolish mistakes. Cheers to their missteps for giving us a good chuckle!