Saturday, May 10, 2025
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
marketibiza
  • Home
  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
    • Life insurance
    • Insurance Law
    • Travel insurance
  • Contact Us
No Result
View All Result
marketibiza
  • Home
  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
    • Life insurance
    • Insurance Law
    • Travel insurance
  • Contact Us
No Result
View All Result
marketibiza
No Result
View All Result
Home Cyber insurance

Who’s Alleged Medibank Hacker Aleksandr Ermakov? – Krebs on Safety

admin by admin
2024年1月29日
in Cyber insurance
0
Who’s Alleged Medibank Hacker Aleksandr Ermakov? – Krebs on Safety
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

You might also like

The Turing check falls to GPT-4.5 • Graham Cluley

Passkeys Set to Shield GOV.UK Accounts Towards Cyber-Assaults

What’s “Rip-off Possible”? Placing the cellphone down on undesirable calls


Authorities in Australia, the UK and america this week levied monetary sanctions in opposition to a Russian man accused of stealing knowledge on almost 10 million prospects of the Australian medical health insurance large Medibank. 33-year-old Aleksandr Ermakov allegedly stole and leaked the Medibank knowledge whereas working with certainly one of Russia’s most harmful ransomware teams, however little extra is shared concerning the accused. Right here’s a more in-depth take a look at the actions of Mr. Ermakov’s alleged hacker handles.

Aleksandr Ermakov, 33, of Russia. Picture: Australian Division of International Affairs and Commerce.

The allegations in opposition to Ermakov mark the primary time Australia has sanctioned a cybercriminal. The paperwork launched by the Australian authorities included a number of images of Mr. Ermakov, and it was clear they needed to ship a message that this was private.

It’s not arduous to see why. The attackers who broke into Medibank in October 2022 stole 9.7 million data on present and former Medibank prospects. When the corporate refused to pay a $10 million ransom demand, the hackers selectively leaked extremely delicate well being data, together with these tied to abortions, HIV and alcohol abuse.

The U.S. authorities says Ermakov and the opposite actors behind the Medibank hack are believed to be linked to the Russia-backed cybercrime gang REvil.

“REvil was among the many most infamous cybercrime gangs on this planet till July 2021 once they disappeared. REvil is a ransomware-as-a-service (RaaS) operation and customarily motivated by monetary acquire,” a statement from the U.S. Division of the Treasury reads. “REvil ransomware has been deployed on roughly 175,000 computer systems worldwide, with a minimum of $200 million paid in ransom.”

The sanctions say Ermakov glided by a number of aliases on Russian cybercrime boards, together with GustaveDore, JimJones, and Blade Runner. A search on the deal with GustaveDore on the cyber intelligence platform Intel 471 exhibits this person created a ransomware associates program in November 2021 known as Sugar (a.ok.a. Encoded01), which targeted on targeting single computers and end-users instead of corporations.

An advert for the ransomware-as-a-service program Sugar posted by GustaveDore warns readers in opposition to sharing data with safety researchers, legislation enforcement, or “mates of Krebs.”

In November 2020, Intel 471 analysts concluded that GustaveDore’s alias JimJones “was utilizing and working a number of completely different ransomware strains, together with a non-public undisclosed pressure and one developed by the REvil gang.”

In 2020, GustaveDore marketed on a number of Russian dialogue boards that he was a part of a Russian expertise agency known as Shtazi, which might be employed for laptop programming, internet growth, and “fame administration.” Shtazi’s web site stays in operation at this time.

A Google-translated model of Shtazi dot ru. Picture: Archive.org.

The third consequence when one searches for shtazi[.]ru in Google is an Instagram publish from a person named Mikhail Borisovich Shefel, who promotes Shtazi’s providers as if it had been additionally his enterprise. If this identify sounds acquainted, it’s as a result of in December 2023 KrebsOnSecurity identified Mr. Shefel as “Rescator,” the cybercriminal id tied to tens of hundreds of thousands of fee playing cards that had been stolen in 2013 and 2014 from massive field retailers Target and Home Depot, amongst others.

How shut was the connection between GustaveDore and Mr. Shefel? The Treasury Division’s sanctions web page says Ermakov used the e-mail handle [email protected]. A seek for this e-mail at DomainTools.com exhibits it was used to register only one area identify: millioner1[.]com. DomainTools additional finds {that a} telephone quantity tied to Mr. Shefel (79856696666) was used to register two domains: millioner[.]pw, and shtazi[.]web.

The December 2023 story right here that outed Mr. Shefel as Rescator famous that Shefel lately modified his final identify to “Lenin” and had launched a service known as Lenin[.]biz that sells bodily USSR-era Ruble notes bearing the picture of Vladimir Lenin, the founding father of the Soviet Union. The Instagram account for Mr. Shefel contains pictures of stacked USSR-era Ruble notes, in addition to a number of hyperlinks to Shtazi.

The Instagram account of Mikhail Borisovich Shefel, aka MikeMike aka Rescator.

Intel 471’s analysis revealed Ermakov was affiliated ultimately with REvil as a result of the stolen Medibank knowledge was revealed on a weblog that had one time been managed by REvil associates who carried out assaults and paid an affiliate payment to the gang.

However by the point of the Medibank hack, the REvil group had largely scattered after a collection of high-profile assaults led to the group being disrupted by legislation enforcement. In November 2021, Europol announced it arrested seven REvil associates who collectively made greater than $230 million price of ransom calls for since 2019. On the identical time, U.S. authorities unsealed two indictments against a pair of accused REvil cybercriminals.

“The posting of Medibank’s knowledge on that weblog, nonetheless, indicated a reference to that group, though the connection wasn’t clear on the time,” Intel 471 wrote. “This is smart looking back, as Ermakov’s group had additionally been a REvil affiliate.”

It’s straightforward to dismiss sanctions like these as ineffective, as a result of so long as Mr. Ermakov stays in Russia he has little to worry of arrest. Nonetheless, his alleged function as an obvious prime member of REvil paints a goal on him as somebody who seemingly possesses massive sums of cryptocurrency, said Patrick Grey, the Australian co-host and founding father of the safety information podcast Dangerous Enterprise.

“I’ve seen a couple of folks poo-poohing the sanctions…however the sanctions element is definitely much less essential than the doxing element,” Grey mentioned. “As a result of this man’s life simply obtained much more sophisticated. He’s in all probability going to should pay some bribes to remain out of bother. Each single prison in Russia now is aware of he’s a weak 33 12 months outdated with an absolute ton of bitcoin. So this isn’t a contented time for him.”

Share30Tweet19
admin

admin

Recommended For You

The Turing check falls to GPT-4.5 • Graham Cluley

by admin
2025年5月9日
0
The Turing check falls to GPT-4.5 • Graham Cluley

In episode 45 of The AI Repair, our hosts uncover that ChatGPT is operating the world, Mark learns that mattress firms have scientists, Gen Z has nightmares about...

Read more

Passkeys Set to Shield GOV.UK Accounts Towards Cyber-Assaults

by admin
2025年5月9日
0
Passkeys Set to Shield GOV.UK Accounts Towards Cyber-Assaults

The UK authorities has unveiled plans to roll out passkeys throughout its digital providers because it seeks to cut back the chance of hacks to individuals’s GOV.UK accounts....

Read more

What’s “Rip-off Possible”? Placing the cellphone down on undesirable calls

by admin
2025年5月8日
0
What’s “Rip-off Possible”? Placing the cellphone down on undesirable calls

Bored with dodging all these 'Rip-off Possible' calls? Here is what’s behind the label and easy methods to keep one step forward of cellphone scammers. 18 Nov 2024...

Read more

third Main UK Retailer Focused In Days

by admin
2025年5月8日
0
third Main UK Retailer Focused In Days

Harrods, the long-lasting British luxurious division retailer, has confirmed that it was just lately focused in a cybersecurity incident, changing into the third main UK retailer in just...

Read more

What’s EDR? An analytical method to endpoint safety

by admin
2025年5月7日
0
What’s EDR? An analytical method to endpoint safety

EDR makes use of extra refined evaluation to detect uncommon person or course of habits or knowledge entry, after which flags or presumably blocks it. Extra importantly, EDR...

Read more
Next Post
Justin Frankel In 2023 Tremendous Attorneys Journal

October is Breast Most cancers Consciousness Month

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
  • Insurance Law
  • Life insurance
  • Travel insurance

Trending News

Insurance coverage is shifting from the admitted to the surplus and surplus market – this is why

Insurance coverage is shifting from the admitted to the surplus and surplus market – this is why

2025年5月9日
Denied Lengthy-Time period Incapacity In Florida? Steps To Take To Shield Your Rights

Denied Lengthy-Time period Incapacity In Florida? Steps To Take To Shield Your Rights

2025年5月9日
The last word information on how you can construct a package automotive

The last word information on how you can construct a package automotive

2025年5月9日
The Turing check falls to GPT-4.5 • Graham Cluley

The Turing check falls to GPT-4.5 • Graham Cluley

2025年5月9日
Frequent Circumstances in Your 40s Influence Life Insurance coverage

Frequent Circumstances in Your 40s Influence Life Insurance coverage

2025年5月9日
Passkeys Set to Shield GOV.UK Accounts Towards Cyber-Assaults

Passkeys Set to Shield GOV.UK Accounts Towards Cyber-Assaults

2025年5月9日
What’s “Rip-off Possible”? Placing the cellphone down on undesirable calls

What’s “Rip-off Possible”? Placing the cellphone down on undesirable calls

2025年5月8日

Market Biz

Welcome to Marketi Biza The goal of Marketi Biza is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

CATEGORIES

  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
  • Insurance Law
  • Life insurance
  • Travel insurance

Recent News

Insurance coverage is shifting from the admitted to the surplus and surplus market – this is why

Insurance coverage is shifting from the admitted to the surplus and surplus market – this is why

2025年5月9日
Denied Lengthy-Time period Incapacity In Florida? Steps To Take To Shield Your Rights

Denied Lengthy-Time period Incapacity In Florida? Steps To Take To Shield Your Rights

2025年5月9日
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2023 Market Biz All Rights Reserved.

No Result
View All Result
  • Home
  • Auto insurance
  • Business insurance
  • Cyber insurance
  • Disability insurance
  • Health insurance
  • Insurance Law
  • Life insurance
  • Travel insurance
  • Contact Us

Copyright © 2023 Market Biz All Rights Reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?