{"id":55949,"date":"2022-01-15T07:00:00","date_gmt":"2022-01-15T05:00:00","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=55949"},"modified":"2025-09-04T04:02:32","modified_gmt":"2025-09-04T01:02:32","slug":"elimination-of-revil-in-russia-attack-on-ukrainian-ministry-websites-and-other-cybersecurity-developments","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/elimination-of-revil-in-russia-attack-on-ukrainian-ministry-websites-and-other-cybersecurity-developments\/","title":{"rendered":"Elimination of REvil in Russia, attack on Ukrainian ministry websites and other cybersecurity developments"},"content":{"rendered":"<p>We\u2019ve gathered the week\u2019s most important cybersecurity news.<\/p>\n<div class=\"wp-block-text-wrappers-keypoints article_keypoints\">\n<ul class=\"wp-block-list\">\n<li>The FSB of Russia said it had eliminated the REvil hackers and their infrastructure. The arrest was carried out at the request of the United States.<\/li>\n<li>Ukrainian government websites were subjected to a cyberattack, described as the largest in the past four years.<\/li>\n<li>According to media reports, Kazakh authorities attempted to use DPI equipment to disconnect the Internet.<\/li>\n<\/ul>\n<\/div>\n<h2 class=\"wp-block-heading\"><strong>FSB says it has eliminated the hacking group REvil<\/strong><\/h2>\n<p>The Russian FSB <a href=\"https:\/\/u1f987.com\/en\/news\/fsb-says-it-dismantled-the-revil-hacker-group\">told<\/a> of the arrest of 14 members of the hacking group REvil (also known as Sodinokibi). It was described as one of the world\u2019s largest hacking groups.<\/p>\n<p>Law enforcement said they had identified all members of the criminal network, and the group itself, as well as its infrastructure, has now been eliminated.<\/p>\n<p>During searches, more than 426 million rubles were seized, including in cryptocurrency, as well as $600 000 and \u20ac500 000.<\/p>\n<p>The arrest followed a request from U.S. authorities, the FSB said.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Media: Kazakh authorities attempted to use DPI equipment to disconnect the Internet<\/strong><\/h2>\n<p>Since the beginning of January, amid protests in Kazakhstan, the Internet has regularly <a href=\"https:\/\/u1f987.com\/en\/news\/bitcoin-hashrate-dips-amid-kazakhstan-internet-shutdown\">shut down<\/a>. Access problems <a href=\"https:\/\/u1f987.com\/en\/news\/mining-data-centres-in-kazakhstan-resume-operations-as-internet-access-is-restored\">continued<\/a> this week as well.<\/p>\n<p>As Forbes reports, originally authorities attempted to block access to messaging apps and websites selectively using deep packet inspection (DPI) equipment. It is used in Russia as part of the so-called sovereign internet law.<\/p>\n<p>However, using DPI for a full network block across the country was not successful.<\/p>\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u00abIt didn\u2019t work because in Kazakhstan DPI is applied not for sovereign internet filtering, but for analysis and prioritisation of traffic. For blockages, you need specialized software, sometimes specialized equipment, and training, which, of course, did not exist in Kazakhstan,\u00bb \u2014 <a href=\"https:\/\/t.me\/roskomsvoboda\/8123\">\u0437\u0430\u044f\u0432\u0438\u043b<\/a> the technical director of Roskomsvoboda, Stanislav Shakirov.<\/p>\n<\/blockquote>\n<p>As a result, authorities ordered operators to completely block the traffic channel, a source familiar with the situation told the media. According to another informant close to the company Kcell, the organisation of blocks is being handled by the Committee for National Security of Kazakhstan without operator involvement.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Hackers attacked Ukrainian government websites<\/strong><\/h2>\n<p>In the night of January 14, hackers carried out a large-scale attack on the websites of Ukrainian ministries and agencies. About 70 pages were affected.<\/p>\n<p>On the sites, attackers posted a message claiming that all residents\u2019 data had been uploaded to a shared network, and that information on computers is destroyed and cannot be recovered.<\/p>\n<p>In Cyber Police, they say there were no leaks of personal data during the attack. Law enforcement is investigating the incident and identifying those involved in the breach.<\/p>\n<p>In the State Service for Special Communications and Information Protection of Ukraine, they stated that this attack was the largest in the last four years.<\/p>\n<h2 class=\"wp-block-heading\"><strong>German authorities did not rule out blocking Telegram<\/strong><\/h2>\n<p>German Interior Minister Nancy Faeser <a href=\"https:\/\/www.zeit.de\/2022\/03\/nancy-faeser-innenministerin-hass-im-netz-impfpflicht\">\u0434\u043e\u043f\u0443\u0441\u0442\u0438\u043b\u0430<\/a> blocking the Telegram messenger on the territory of the country, emphasising that this would be an extreme measure.<\/p>\n<p>The reason is the service\u2019s use by criminals to disseminate illegal content.<\/p>\n<h2 class=\"wp-block-heading\"><strong>In France, Google and Meta were fined multimillion-euro over cookies<\/strong><\/h2>\n<p>The French regulator fined Google a record \u20ac150 million for not giving users an easy way to refuse tracking via cookies. For the same reason, France fined Meta Platforms \u20ac60 million, according to <a href=\"https:\/\/www.reuters.com\/world\/europe\/france-imposes-fines-facebook-ireland-google-2022-01-06\/\">Reuters<\/a>.<\/p>\n<p>Companies have three months to provide French users with easier tools to opt out of cookies. Otherwise they face an additional penalty of \u20ac100,000 per day of delay.<\/p>\n<h2 class=\"wp-block-heading\"><strong>The largest dark web marketplace for selling stolen credit cards closes<\/strong><\/h2>\n<p>UniCC, the largest dark web platform for selling stolen credit card data, announced its closure, according to <a href=\"https:\/\/www.elliptic.co\/blog\/unicc-the-largest-dark-web-vendor-of-stolen-credit-cards-retires-after-raking-in-358-million-in-crypto\">Elliptic<\/a>.<\/p>\n<p>UniCC has operated since 2013. Over this period the marketplace operators received payments totaling $358 million in Bitcoin, Litecoin, Ethereum and Dash.<\/p>\n<p>Also on ForkLog:<\/p>\n<ul class=\"wp-block-list\">\n<li>Hackers withdrew nearly $8 million from the LCX exchange\u2019s hot wallet <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-siphon-nearly-8-million-from-lcxs-hot-wallet\">.<\/li>\n<li>In Ukraine <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-distributing-ransomware-uncovered-in-ukraine-losses-exceed-1-million\">they discovered<\/a> hackers distributing ransomware. The damage exceeded $1 million.<\/li>\n<li>Chainalysis experts calculated that in 2021 crypto scammers earned a record $14 billion. They also found that <a href=\"https:\/\/u1f987.com\/en\/news\/chainalys%d1%96s-in-2021-north-korean-hackers-stole-400-million-in-cryptocurrencies\">hackers from DPRK stole $400 million in cryptocurrencies<\/a> last year.<\/li>\n<li>Avira added <a href=\"https:\/\/u1f987.com\/en\/news\/avira-antivirus-adds-ethereum-mining-software\">software for Ethereum mining<\/a>.<\/li>\n<li>Hackers <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-modify-the-dnspy-debugger-for-covert-cryptocurrency-mining\">modified<\/a> the dnSpy debugger to enable covert cryptocurrency mining.<\/li>\n<li>Group-IB identified <a href=\"https:\/\/u1f987.com\/en\/news\/group-ib-identifies-8000-fraudulent-domains-targeting-crypto-and-stock-investors\">8,000 fraudulent domains<\/a> aimed at cryptocurrency and stock investors.<\/li>\n<li>Attackers <a href=\"https:\/\/u1f987.com\/en\/news\/hackers-siphon-18-million-from-animoca-brands-lympo-platform\">withdrew $18 million<\/a> from the Lympo platform by Animoca Brands.<\/li>\n<li>Check Point Research analysts reported a <a href=\"https:\/\/u1f987.com\/en\/news\/cyberattacks-doubled-in-2021-russia-leads\">50% increase in 2021 in cyberattacks on corporate networks<\/a>.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\">What to read this weekend?<\/h2>\n<p>Cyberattacks, QR-code proliferation amid the pandemic, and the end of the era of self-regulation of social networks \u2014 a recap of what happened to internet freedom and cybersecurity last year.<\/p>\n<p>Read ForkLog\u2019s Bitcoin news in our <a href=\"\/\/telegram.me\/forklog\" target=\"\u201c_blank\u201d\" rel=\"\u201cnofollow\u201d noopener\">Telegram<\/a> \u2014 cryptocurrency news, prices and analytics.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We\u2019ve gathered the week\u2019s most important cybersecurity news.<\/p>\n","protected":false},"author":1,"featured_media":55950,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"1","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1238,1233],"class_list":["post-55949","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-cybersecurity-digest","tag-industry-digests"],"aioseo_notices":[],"amp_enabled":true,"views":"21","promo_type":"1","layout_type":"1","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/55949","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=55949"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/55949\/revisions"}],"predecessor-version":[{"id":55951,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/55949\/revisions\/55951"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/55950"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=55949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=55949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=55949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}