bitcoin
Bitcoin (BTC) $ 63,234.94 0.51%
ethereum
Ethereum (ETH) $ 2,561.36 0.45%
tether
Tether (USDT) $ 1.00 0.08%
bnb
BNB (BNB) $ 584.73 3.06%
solana
Solana (SOL) $ 147.84 0.02%
staked-ether
Lido Staked Ether (STETH) $ 2,559.50 0.45%
usd-coin
USDC (USDC) $ 1.00 0.09%
dogecoin
Dogecoin (DOGE) $ 0.109132 4.40%
xrp
XRP (XRP) $ 0.597056 3.11%
shiba-inu
Shiba Inu (SHIB) $ 0.000015 5.85%
cardano
Cardano (ADA) $ 0.358130 1.67%
avalanche-2
Avalanche (AVAX) $ 27.55 1.80%
the-open-network
Toncoin (TON) $ 5.65 1.35%
wrapped-bitcoin
Wrapped Bitcoin (WBTC) $ 63,138.92 0.49%
bitcoin-cash
Bitcoin Cash (BCH) $ 342.09 2.34%
tron
TRON (TRX) $ 0.152441 0.38%
pepe
Pepe (PEPE) $ 0.000008 2.24%
litecoin
Litecoin (LTC) $ 66.54 2.83%
internet-computer
Internet Computer (ICP) $ 8.55 2.31%
fetch-ai
Artificial Superintelligence Alliance (FET) $ 1.64 2.54%

Ransomware gang BlackCat exit scams affiliates with millions in Bitcoin after attacking


Cyber gang BlackCat allegedly scammed its own affiliates as the group went dark shortly after it disrupted the U.S. healthcare system.

An address associated with the ransomware gang BlackCat, also known as ALPHV and Noberus, received approximately $22 million worth of Bitcoin (BTC) on Mar. 1 following a late February attack on United Healthcare’s Change Healthcare, a tech firm providing services to hospitals and clinics.

However, a twist emerged two days later when the address received over 1,000 BTC and promptly emptied the wallet. Subsequently, an individual named “notchy,” claiming to be an affiliate of BlackCat, alleged in a post on a cybercriminal underground forum that the gang had deceived its affiliates as it didn’t pay them their share for executing the attack, according to a copy of the message shared on X by Dmitry Smilyanets, Recorded Future’s product management director.

The affiliate further disclosed that the attack on Change Healthcare’s network had granted access to the data of numerous other healthcare firms partnered with the medical IT provider. In a statement to Wired, Smilyanets confirmed that the affiliates “still have this data, and they’re mad they didn’t receive this money.”

Both Recorded Future and TRM Labs, a blockchain analysis firm, have reportedly identified the Bitcoin address that received nearly $100 million in Bitcoin as linked to the BlackCat hackers. According to MistTrack, all the BTC allegedly connected to illicit activity has been transferred to eight different addresses and remains unspent thus far.

Established in late 2021, BlackCat operated on a ransomware-as-a-service model, providing affiliates with malware and taking a percentage of ransom payments. Having targeted numerous companies worldwide, including Reddit in 2023, the gang’s website was shut down by the FBI in December 2023, resulting in the seizure of multiple websites and the release of a decryption tool.

However, in February 2024, the U.S. Department of State annoucned a reward offering of up to $10 million for information leading to the identification or location of individuals holding key leadership positions within the BlackCat group and up to $5 million for information leading to the arrest or conviction of anyone involved in the group.


Follow Us on Google News



Read More: Ransomware gang BlackCat exit scams affiliates with millions in Bitcoin after attacking

Disclaimer:The information provided on this website does not constitute investment advice, financial advice, trading advice, or any other sort of advice and you should not treat any of the website’s content as such. NewsOfBitcoin.com does not recommend that any cryptocurrency should be bought, sold, or held by you. Do conduct your own due diligence and consult your financial advisor before making any investment decisions.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments