{"id":225897,"date":"2017-07-05T19:01:58","date_gmt":"2017-07-05T23:01:58","guid":{"rendered":"http:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/uncategorized\/hackers-who-targeted-ukraine-clean-out-bitcoin-ransom-wallet-the-guardian.php"},"modified":"2017-07-05T19:01:58","modified_gmt":"2017-07-05T23:01:58","slug":"hackers-who-targeted-ukraine-clean-out-bitcoin-ransom-wallet-the-guardian","status":"publish","type":"post","link":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/bitcoin-2\/hackers-who-targeted-ukraine-clean-out-bitcoin-ransom-wallet-the-guardian.php","title":{"rendered":"Hackers who targeted Ukraine clean out bitcoin ransom wallet &#8230; &#8211; The Guardian"},"content":{"rendered":"<p><p>  transferred to a second wallet on Tuesday night. Photograph:  Bloomberg\/Bloomberg via Getty Images<\/p>\n<p>    The hackers behind the NotPetya ransomware, which wiped    computers in more than 60 countries in late June, have moved    more than 8,000 worth of bitcoins out of the account used to    receive the ransoms.  <\/p>\n<p>    The transfer has added credence to messages purporting to be from the attackers    offering to    decrypt every single infected computer for a one-off    payment of 200,000, after security researchers suggested they    may be state-sponsored actors.  <\/p>\n<p>    It is possible to see the movement of the ransom payments    thanks to the public nature of the bitcoin currency: all    transfers are recorded on the public blockchain, although the    real-world identities of the individuals or organisations    behind a particular payment address can be near-impossible to    discern.  <\/p>\n<p>    Currently, the blockchain records that the bulk of the ransom    money, 7,872 worth of bitcoin, was simply    transferred to a second wallet on Tuesday night, but two    smaller payments, of 200 each, went to accounts used by two    text-sharing websites, Pastebin and DeepPaste.  <\/p>\n<p>    Around 10 minutes before the payments were made, someone made    posts on both those sites claiming to be able to decrypt hard    disks infected with the malware in exchange for a payment of    100 bitcoins.  <\/p>\n<p>    The 200,000 offer has created more uncertainty about the    motivations behind the ransomware. While it originally appeared    to be created with the intention of earning a lot of money    through ransom payments, researchers quickly pointed out that a    number of features of the software made it appear that the    ransom element was a smokescreen, with the real    goal being widespread damage.  <\/p>\n<p>    Significantly, the majority of infections occurred in Ukraine, due to the main attack vector being    a compromised version of an accounting program, ME Doc, used to    file taxes in the nation. That has led to many, including the    Ukrainian government, suspecting Russian involvement as part of    the ongoing cyberwar between the two countries.  <\/p>\n<p>    Hackers offering to decrypt files for money suggests that the    cash motivation may be more significant than thought  but that    too could be misdirection.  <\/p>\n<p>    While the hackers continue to play games, the Ukrainian    cybercrime unit is continuing its investigation. On Wednesday,    it announced that it had seized ME Docs servers after new    activity was detected there, and said it had acted to    immediately stop the uncontrolled proliferation of malware.  <\/p>\n<p>    Cyber police spokeswoman Yulia Kvitko suggested that ME Doc had    sent or was preparing to send a new update and added that swift    action had prevented any further damage. Our experts stopped    (it) on time, she said.  <\/p>\n<p>    It wasnt immediately clear how or why hackers might still have    access to ME Docs servers. The company has not returned    messages from reporters, but in several statements took to    Facebook to dispute allegations that its poor security helped    seed the malware epidemic.  <\/p>\n<p>    Cyber police chief Coonel Serhiy Demydiuk previously said that    ME Docs owners would be brought to justice, but Kvitko said    there had been no arrests.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>Read more here: <\/p>\n<p><a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.theguardian.com\/technology\/2017\/jul\/05\/notpetya-ransomware-hackers-ukraine-bitcoin-ransom-wallet-motives\" title=\"Hackers who targeted Ukraine clean out bitcoin ransom wallet ... - The Guardian\">Hackers who targeted Ukraine clean out bitcoin ransom wallet ... - The Guardian<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> transferred to a second wallet on Tuesday night. Photograph: Bloomberg\/Bloomberg via Getty Images The hackers behind the NotPetya ransomware, which wiped computers in more than 60 countries in late June, have moved more than 8,000 worth of bitcoins out of the account used to receive the ransoms. The transfer has added credence to messages purporting to be from the attackers offering to decrypt every single infected computer for a one-off payment of 200,000, after security researchers suggested they may be state-sponsored actors.  <a href=\"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/bitcoin-2\/hackers-who-targeted-ukraine-clean-out-bitcoin-ransom-wallet-the-guardian.php\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"limit_modified_date":"","last_modified_date":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[261455],"tags":[],"class_list":["post-225897","post","type-post","status-publish","format-standard","hentry","category-bitcoin-2"],"modified_by":null,"_links":{"self":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/225897"}],"collection":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/comments?post=225897"}],"version-history":[{"count":0,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/posts\/225897\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/media?parent=225897"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/categories?post=225897"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.euvolution.com\/futurist-transhuman-news-blog\/wp-json\/wp\/v2\/tags?post=225897"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}