Russian hackers are raking in ransomware rewards

Ransomware
Image credit: Shutterstock (Image credit: Shutterstock)

Most of the money made from ransomware operations ends up in the hands of Russian-speaking threat actors, a report from market analysts Chainalysis claims.

Speaking to the BBC, Chainalysis says 74% of all money stolen through ransom demands in 2021 went to threat actors linked to Russia, in one way or another - equivalent to more than $400 million worth of cryptocurrencies.

What’s more, Chainalysis claims that “a huge amount of cryptocurrency-based money laundering” is being conducted by Russian cryptocurrency companies, as well.

Refraining from attacking Russian-speaking businesses

Most cryptocurrencies are easy to track. Their respective blockchains (the technology underpinning the tokens, or coins) are usually transparent, meaning that specific coins can easily be tracked through time. Also, specific cryptocurrency wallets can be monitored freely. 

But it’s not just wallets and money that the researchers are tracking. The BBC also reported that the malware usually used in ransomware attacks displays unique characteristics like being prevented, at code-level, from damaging files and companies on endpoints located in Russia, or other Russian-speaking countries. 

The gangs that distribute the ransomware usually hang out on Russian-speaking forums, and they are often linked to Evil Corp, a threat actor group wanted by the US which, Chainalysis claims, takes almost 10% of all ransomware revenue.

The problem with this line of thinking, BBC also adds, is that many of the ransomware threat actors work on a RaaS principle, offering Ransomware as a service to whoever is willing to pay. 

Russia, on the other hand, has denied the accusations of facilitating cyber-criminals. To that end, it reminded of the dismantling of the REvil ransomware operators, which it did at the request of the States.

Still, one of Evil Corp’s alleged leaders, Igor Turashev, is running multiple businesses from Moscow City’s Federation Tower, one of the country’s “most prestigious” addresses, the BBC added. 

"In any given quarter, the illicit and risky addresses account for between 29% and 48% of all funds received by Moscow City crypto-currency businesses", Chainalysis concluded.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
A group of 7 hackers, 6 slightly blurred in the background and one in the foreground, all wearing black with hoods pulled up over their heads. You cannot see their faces. The hacker in the foreground sits with an open laptop in front of them. The background, behind the hackers, is a Chinese flag
China government-linked hackers caught running a seriously dangerous ransomware scam
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
More reports claim 2024 was the worst year for ransomware attacks yet
Flags of Iran, China, Russia and North Korea on a wall. China North Korea Iran Russia alliance
Cybercrime is helping fund rogue nations across the world - and it's only going to get worse, Google warns
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Latest in News
Nvidia geforce rtx 3050
RTX 5050 rumors detail full spec of desktop graphics card, suggesting Nvidia may use slower video RAM – but I wouldn’t panic yet
OnePlus 13
OnePlus is ditching the Alert Slider for an iPhone-style customizable button - and I’ll be sad to see it go
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
Q Acoustics Q SUB80, QSUB100 and QSUB120 subwoofers
Q Acoustics wants to bring the bass to your post-Oscars movie catch-up
Hospital
Major Oracle outage hits US Federal health record systems
Samsung Galaxy A56 display
Samsung’s new budget handsets are getting One UI 7 before the Galaxy S24 Ultra, and I’m as confused as you are