Reuters reported that a cyber extortion gang suspected to be an offshoot of the notorious Russian "Conti" hacking group has defrauded more than $100 million since its emergence last year, researchers said in a report released on Wednesday.
A ransom-seeking cybercriminal group known as "BlackBasta" has extorted at least $107 million in Bitcoin, with much of the laundered ransom going to sanctioned Russian cryptocurrency exchange Garantex, digital currency tracking services Elliptic and Corvus Insurance said in a joint report.
Attempts to contact BlackBasta via its dark website were not immediately successful. Garantex, which was sanctioned by the U.S. Treasury Department last April, did not immediately respond to messages.
Elliptic co-founder Tom Robinson said the large number of attacks made BlackBasta "one of the most profitable ransomware ever." He said researchers arrived at the figure by identifying known ransom payments associated with the group and tracing how digital currencies were laundered, revealing additional sources of funds.
Robinson said the investigation also found millions of dollars worth of Bitcoin moved from cryptocurrency wallets associated with Conti, a now-defunct ransomware gang, to BlackBasta, which he said provided "significant new evidence" that the latter was an offshoot of the group. previous.
Conti was once one of the internet's major ransomware gangs, which coerced victims into submission by either encrypting their data and demanding money to decrypt it, threatening to release stolen information online, or both. After the Kremlin invaded Ukraine in early 2022 and the U.S. government placed a bounty on the extortion group's leadership, the Russia-based group later dismantled its leak website, but researchers have long suspected that the group was reorganized, or simply renamed.
"Conti is probably the most successful ransomware gang we've ever seen," Robinson said. The latest findings indicate that "some responsible individuals are using BlackBasta ransomware to replicate its success."