FBI Confirms DarkSide Behind Colonial Pipeline Hack
The FBI has declared that the DarkSide hacking collective is behind the shutdown.
Published 3 years ago in Ouch
8
Experts believe that DarkSide, like REvil, are based in Russia or a former Soviet-bloc nation. Code found in their ransomware first checks the target computer's language; if the ransomware detects it is Russian, it ceases its attack and moves on. Thus far, only English-speaking for-profit businesses have been targeted by DarkSide.
9
In an announcement on their dark web site, DarkSide seemed to claim that the widespread disruption and potential cost to the consumer caused by their hack were unintended, stating "From today we introduce moderation and check each company that our partners want to encrypt to avoid social consequences in the future." This is likely part of their self-professed code of ethics that prohibits them from targeting certain entities, namely hospitals, funeral homes and non-profit organizations.
11
Perhaps in response to Biden's statement, DarkSide denied any affiliation with the Russian government, stating “We are apolitical, we do not participate in geopolitics, do not need to tie us with a defined government and look for our motives" and that their singular goal was to "make money, and not to create "problems for society."