New ‘DarkBit’ ransomware gang shuts down Technion, demands $1.7 million ransom

Viking

Level 26
Thread author
Verified
Honorary Member
Top Poster
Well-known
Oct 2, 2011
1,534

A politically charged ransom note suggests DarkBit are one of the newest hacktivist gangs to emerge in recent months​

A cyber attack on the Israel Institute of Technology has brought to light the emergence of a potentially aggressive new ransomware gang, DarkBit.
The institute, known as Technion, was struck by a ransomware attack over the weekend during which hackers demanded an 80-Bitcoin ransom, equivalent to around $1.7 million (£1.4 million).
In the ransomware note, the group threatened to raise the ransom sum by 30% if the academic institution failed to pay the ransom in a 48-hour period.

The ransomware note was also littered with anti-Israeli government rhetoric, suggesting that the attack was politically motivated.
Believed to be a hacktivist operation, the likelihood of a victim paying DarkBit and then later receiving the decryptor is generally lower since the attack isn't believed to be wholly motivated by money.
“We’re sorry to inform you that we had to hack Technion network completely and transfer 'all' data to our secure servers,” the note read.
“So, keep calm, take a breath and think about an apartheid regime that causes troubles here and there.”
The Israel Institute of Technology was hit by ransomware this morning.- DarkBit ransomware (???)- Ransom note is political- Attackers want $1,700,000+ (80 BTC)- Ransom note is written using an English translatorImage courtesy of @CyberIL pic.twitter.com/jUjK9CvAhp
— vx-underground (@vxunderground) February 12, 2023
Technion confirmed it was dealing with a security incident in a statement online on Sunday 12 February, adding that it was working to determine the full scale of exposure.
“The Technion is under cyber attack. The scope and nature of the attack are under investigation,” the statement read, “To carry out the process of collecting the information and handling it, we use the best experts in the field, in the Technion and outside, and coordinate with the authorities.”


While the exact scale of the attack is yet to be disclosed, the university said in a follow-up statement that campus activity, including exams, would not be affected.
 
Last edited by a moderator:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top