BlackMatter ransomware group may have shut down operations

[Ed. Note: This piece has been updated to include information about BlackCat, which has potential links to BlackMatter.]

The U.S. Department of Health and Human Services’ cybersecurity arm released a bulletin this week with some rare good news: The BlackMatter ransomware-as-a-service program appears to have shut down operations.  

“While [the Health Sector Cybersecurity Coordination Center] previously identified multiple healthcare and public health (HPH) sector or health sector-affiliated organizations impacted by this malware, the group has not claimed a victim since October 31, 2021,” said the HC3 analyst note.  

As such, HC3 reduced the threat level posed by the group from “yellow,” or “elevated,” to “blue,” or “guarded.” 

WHY IT MATTERS  

BlackMatter is a Russian-speaking group with likely origins in Eastern Europe.   

Although the operation claimed not to target healthcare entities, HC3 considered it to be a highly sophisticated operation that posed an “elevated risk” to the sector; in September, the agency released a briefing warning as much

In fact, HC3 said it is aware of at least four healthcare or healthcare-related organizations that have been impacted by BlackMatter ransomware incidents – including a medical testing and diagnostics company, a pharmaceutical consulting company, and a dermatology clinic, all in the United States.  

“A global medical technology company based in the Asia-Pacific region also suffered a BlackMatter incident,” read the analyst note.  

In October, federal agencies issued a Cybersecurity Advisory providing information on BlackMatter ransomware, suggesting that the group is a possible rebrand of the DarkSide ransomware-as-a-service organization. And on Wednesday, some analysts said that BlackCat, the ransomware group possibly behind a recent attack on two German oil companies, is likely another rebrand.

However, October was the same month BlackMatter appeared to claim its last victim.  

“On November 1, BlackMatter claimed it was shutting down operations following pressure from local law enforcement and stated that key members of its group were ‘no longer available,'” said the HC3 note.  

“Shortly thereafter, the existing BlackMatter victims were moved to the competing LockBit ransomware negotiation site,” it continued.  

THE LARGER TREND  

BlackMatter’s predecessor, REvil, has also receded from the threat landscape following several high-profile attacks on healthcare organizations.  

In November, the U.S. Department of Justice announced that it had taken action against two individuals accused of using the ransomware to attack U.S. businesses and government agencies.

“The arrest of Yaroslav Vasinskyi, the charges against Yevgeniy Polyanin and seizure of $6.1 million of his assets, and the arrests of two other Sodinokibi/REvil actors in Romania are the culmination of close collaboration with our international, U.S. government and especially our private sector partners,” said FBI Director Christopher Wray in a statement at the time.  

ON THE RECORD  

“HC3 can confirm that the BlackMatter leak site is no longer operational and no known ransomware variants are believed to be successors at this time, according to open source reporting,” said the agency.

Still, it warned, “While the group appears to have shut down operations, other actors seeking lucrative payouts from ransomware attacks are likely to fill this void.”  

Kat Jercich is senior editor of Healthcare IT News.
Twitter: @kjercich
Email: kjercich@himss.org
Healthcare IT News is a HIMSS Media publication.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
'I'm childless and nearing 30 thumbnail

‘I’m childless and nearing 30

Last week, the Office for National Statistics revealed that over half of women in UK (well just, it's 50.1%) haven't had a child by the time they reach their milestone 30th birthday. I'm 28 and childless, and it can often seem like everyone around me is having a baby, especially because most of my best…
Read More
עמילואידוזיס מסוג טרנסתירטין לבבי: פנים חדשות למחלה 'ישנה' thumbnail

עמילואידוזיס מסוג טרנסתירטין לבבי: פנים חדשות למחלה ‘ישנה’

מאת דר' אורטל טובלי ופרופ' יעקב ג'ורג', המערך הקרדיולוגי מרכז רפואי קפלן והאוניברסיטה העברית "עמילואידוזיס" (Amyloidosis) הינו מושג כללי המתייחס לקבוצת מחלות רב מערכתיות הנובעות משקיעה חוץ תאית של חלבון בלתי מסיס מסוג עמילואיד בצורתו הלא טבעית והלא יציבה. שקיעת העמילואיד עלולה להתרחש באופן מקומי או רב מערכתי וסוג העמילואידוזיס נקבע על פי סוג החלבון…
Read More
Tinder Swindler, Simon Leviev, Speaks Out After The Documentary thumbnail

Tinder Swindler, Simon Leviev, Speaks Out After The Documentary

Simon Leviev, the infamous ‘Tinder Swindler,’ has broken his silence since the Netflix documentary aired. During an interview with Inside Edition, the Israeli-born con artist has denied any wrongdoing. Simon, aka Shimon Hayut, was quoted as saying, “I’m not this monster. I was just a single guy that wanted to meet some girls on Tinder.”…
Read More
One-Pan Thai Red Curry Salmon thumbnail

One-Pan Thai Red Curry Salmon

One-Pan Thai Red Curry Salmon By: Lisa Guy Easy to prepare and full of wholesome ingredients, this salmon dish is a delicious way to nourish your body in just one pot. Salmon is rich in omega-3 fatty acids, which support heart health, brain function, and reduce inflammation. This fragrant Thai red curry is loaded with
Read More
Index Of News
Total
0
Share