Security News > 2023 > November > Russian-speaking threat actor "farnetwork" linked to 5 ransomware gangs
In interactions with threat intelligence analysts, farnetwork shared valuable details that link them to ransomware operations starting 2019 and a botnet with access to multiple corporate networks.
According to a report Group-IB shared with BleepingComputer, the threat actor has several usernames and has been active on multiple Russian-speaking hacker forums trying to recruit affiliates for various ransomware operations.
Based on Group-IB's findings, farnetwork is suspected to have been involved in developing or at least in the evolution and management of the mentioned ransomware strains.
Group-IB managed to connect the different usernames to the same threat actor, showing that ransomware operations can come and go but behind them are seasoned individuals that keep the business going under new names.
ShadowSyndicate hackers linked to multiple ransomware ops, 85 servers.
US sanctions Russian who laundered money for Ryuk ransomware affiliate.
News URL
Related news
- US Government, Microsoft Aim to Disrupt Russian threat actor ‘Star Blizzard’ (source)
- Volkswagen monitoring data dump threat from 8Base ransomware crew (source)
- Crypt Ghouls Targets Russian Firms with LockBit 3.0 and Babuk Ransomware Attacks (source)
- Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions (source)
- Russian suspected Phobos ransomware admin extradited to US over $16M extortion (source)