Four cybercrime sleuths from Singapore-based cybersecurity firm Group-IB have revealed how they infiltrate ransomware gangs in order to gather crucial information and mitigate further damage. The hackers are able to break into the cybercriminals’ ranks by conducting extensive research into the ransomware-as-a-service (RaaS) groups, including gathering intelligence on their operations, identifying contact information for the ransomware managers, and establishing communication through encrypted messengers. The researchers then undergo an interview process, in which they are quizzed on their experience with attacking organizations and their knowledge of the ransomware landscape. They must also demonstrate technical expertise and an understanding of the tools used in attacks. Once they pass the interview stage and gain the trust of the ransomware group, they are able to gather valuable information, such as the number of attacks, payment structures, and insights into how affiliates build custom ransomware payloads. However, the researchers are clear that they never engage in illegal activities, and their primary objective is to gather information to mitigate further damage. The information they gather during these infiltrations helps inform investigative activities and industry-wide mitigation efforts. The researchers emphasize the importance of operating within the confines of the law and not engaging in unlawful activities, as this would make them indistinguishable from cybercriminals themselves. Despite the inherent limitations of these infiltrations, Group-IB believes they are worth the outlay of resources as they provide valuable insights into the operations of ransomware groups and help protect customers against the threat of ransomware.
Decrypting cybercriminals: Experts unveil secrets to infiltrate ransomware gangs!
![](https://cybsecwizard.com/wp-content/uploads/2023/12/The-Importance-of-Financial-Literacy-Apps.jpg)
Latest from Blog
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Fintech-vs-Traditional-Banks_-A-Comparative-Analysis.jpg)
US charges North Korean hacker for hospital ransomware attacks
TLDR: The U.S. DoJ indicted a North Korean hacker for ransomware attacks on hospitals The hacker, Rim Jong Hyok, is part of a group called Andariel and is accused of laundering ransom
![](https://cybsecwizard.com/wp-content/uploads/2023/12/The-Battle_-Fintechs-vs-Traditional-Banks.jpg)
Deadline approaching for Cyber Security Framework adoption and mandatory reporting Regulator shifts focus to enforcement from education
TLDR: Key points: Important compliance dates approaching for critical infrastructure assets under the Security of Critical Infrastructure Act. Responsible entities must adhere to specific cyber security frameworks and submit mandatory annual reports.
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Decoding-Fintech-Licenses.jpg)
Cyberattack hits Selenium Grid for Crypto Mining – stay safe
Ongoing Cyberattack Targets Exposed Selenium Grid Services TLDR: Cyberattack targeting older versions of Selenium for crypto mining Threat actors using Selenium Grid services for illicit activities Cybersecurity researchers are warning about an
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Quantum-Computing-and-Finance.jpg)
Bridging the cyber talent gap: tips for CISOs
TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Demystifying-Fintech-Operations_-How-They-Work-and-Compete.jpg)
Deepfake dangers prompt urgent cybersecurity reevaluations for businesses
TLDR: AI-generated deepfake attacks are on the rise, leading companies to reassess their cybersecurity measures. Companies are developing deepfake response plans and running simulations to increase preparedness. Biometric authentication, once considered secure,
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Fintech-in-Emerging-Markets.jpg)
North Korean faces charges for cyberattacks on US targets
TLDR: A North Korean military intelligence operative has been indicted for orchestrating cyberattacks on U.S. hospitals, NASA, and military bases. Rim Jong Hyok, a member of the Andariel Unit, faces charges of
![](https://cybsecwizard.com/wp-content/uploads/2023/12/The-Role-of-AI-in-Fintech.jpg)
Analysts predict cybersecurity stocks will soar after CrowdStrike’s outage
“`html TLDR: CrowdStrike outage led to potential gains for cybersecurity rivals SentinelOne, Palo Alto Networks, and Microsoft’s cybersecurity business could benefit After a defective CrowdStrike update caused a global tech outage, analysts
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Fintech-in-Retail_-Enhancing-Customer-Experiences.jpg)
Bitsight’s Trust Management Hub: Revolutionizing Security Assessment Process
TLDR: Bitsight has released Trust Management Hub to streamline security assessments. The new solution reduces workload by 25% and improves the assessment cycle by 85%, helping teams close deals faster. Bitsight, a
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Bridging-Financial-Inequality_-Fintechs-Role-and-Potential.jpg)
North Korean hackers pivot to ransomware attacks
TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat
![](https://cybsecwizard.com/wp-content/uploads/2023/12/Fintech-in-Emerging-Markets.jpg)
Europe’s telecom, electricity sectors evaluated in new EU cybersecurity report
TLDR: EU releases risk assessment report on cybersecurity in telecommunications and electricity sectors Report highlights supply chain risks, shortage of cybersecurity professionals, and threats from cybercriminals and state-sponsored actors Summary: The European