Biden warns Putin to act on Russian ransomware group



[ad_1]

Friday’s call came just three weeks after the onslaught of ransomware attacks dominated their first summit, in Geneva. Immediately after the meeting, Biden said he told the Russian president he would react “cybernetically” against Russia if Mr. Putin did not take action against groups operating in his territory.

But that three-hour meeting was largely a generic discussion of the issue and an effort to convince Mr. Putin that the presence of cybercrime groups on Russian networks was also not in Moscow’s interest. By calling right after REvil’s last attack, he was essentially creating a test of Mr. Putin’s willingness to act. But Mr Biden declined to say whether the United States has called for specific action against individuals they say are part of REvil.

While the United States and Russia have long fought against state-sponsored attacks – including the SolarWinds spy operation by Russian elite intelligence agency SVR, or the hack by the unit Russian military intelligence report from the Democratic National Committee and its publication of embarrassing emails in 2016 – ransomware attacks are of a different nature. Administration officials fear that if left unaddressed they could cripple key sectors of the U.S. economy. And they suspect the Russian authorities are tolerating the groups – and sometimes tapping into their talent pool for intelligence and other cyber operations.

The White House has blamed a Russian ransomware group, called DarkSide, for the attack on Colonial Pipeline that halted deliveries of gasoline and jet fuel to the east coast this spring. REvil is believed to be behind the attack on one of the country’s largest meat processors, JBS, which briefly halted production in late May. The company paid REvil $ 11 million in cryptocurrency.

But REvil’s attack during the July 4 break was an escalation, officials said, not only for its timing after the Geneva summit, but because the attack was unusually advanced in technique and aggressive in scope. Instead of directly targeting a company, REvil raped a Florida tech company that has high-profile access to tech companies that serve thousands of other businesses. Had the company, Kaseya, not detected the attack early, the effects could have been cataclysmic, according to officials and cybersecurity experts.

Mr Biden’s challenge to Mr Putin could serve as a major test of credibility in the weeks to come – and further exacerbate a series of Cold War-like confrontations between the United States and Russia, now conducted in cyberspace rather than ‘through the Berlin Wall.

Until recently, the United States largely viewed ransomware as a criminal problem, charging key players if they could identify them. Few people have ever seen the interior of an American courtroom.

[ad_2]

Source link