- Feb 4, 2016
- 2,520
....some quotes from the article:
All the Bitcoins paid by victims of the NotPetya ransomware attack were withdrawn overnight.
Some paid the equivalent of $300 in Bitcoin even though there were no means to recover their data. Just over 3.96 Bitcoin ($10,382) was withdrawn from a wallet tied to NotPetya early on Wednesday morning, according to a RPi bot tweeting out activity on the Bitcoin wallet tied to the Petya ransomware attack.
These funds were used to pay for a Pastebin Pro account on the dark web, which was subsequently used to post fresh ransomware drop instructions.
As previously reported, NotPetya trashes compromised systems and acts more like a wiper than conventional ransomware. Though alternate means of recovering data have been discovered, it's still unlikely to be any help, so payment would still be a waste.
NotPetya spread to devastating effect last week using a variety of mechanisms. A poisoned update to a Ukrainian tax software program called M.E.Doc was the primary initial infection vector, according to security researchers.