Russian Groove Ransomware Gang Attempts to Rally Hackers Against the US
As though the situation on the ransomware landscape was not complicated enough, new fuel has been poured on the fire, with a disturbing statement coming from one Russian-language ransomware gang.
The Groove ransomware group has updated its blog with a new post, containing an open letter of sorts, addressed to all Russian-speaking ransomware gangs. The blog post is a rallying cry for all Russian cyber gangs to abandon their internal struggles and competition and unite in a joint effort to act against US interests at large.
The letter uses particularly flowery language and makes several very interesting points, in addition to appealing to all Russian-speaking hackers to unite and coordinate their attacks against US entities. The Groove hackers also specifically make a point of not attacking China and call the country a "good neighbor".
The reasoning provided in the blog post is that hackers operating out of Russia will be able to turn to the same "good neighbor" in case Russian authorities really tighten the noose and get them on the run, whether this happens through external pressure or not.
This somewhat unexpected and bold move on part of Groove and Russian-speaking ransomware threat actors comes in the wake of the international operation that led to the shutdown of a major part of the infrastructure of the REvil ransomware gang. The REvil gang was behind the two highest-impact ransomware attacks of the year so far - the ones against Colonial Pipeline and JBS - America's largest supplier of meat.
Both of those attacks led to significant disruption, particularly the one against Colonial Pipeline, which left a large part of the US East coast short on liquid fuel for days on end. This led to the exchange of pointed words between the US and the Kremlin and culminated in the involvement of US federal agencies in the REvil takedown operation.
This was very likely the trigger that caused the attempt for retaliation on part of the Groove ransomware gang. It is too early to tell whether anyone will respond to the rallying call of the hackers and whether we will see further coordinated, joint attacks on US companies and organizations. At any rate, IT security in all sectors should be heightened more than ever to prepare for a possible massive cyber attack.








